c51691985319[.]ngrok-free[.]app
“ERR_NGROK_6024 - You are about to visit c51691985319.ngrok-free.app, served by 185.150.25.240. This…”
c51691985319.ngrok-free.app — Контент недоступний. Зведення доказів: VirusTotal 6/95 (alphaMountain.ai, CyRadar, Dr.Web, ESET, Fortinet); PhishDestroy score 68/100. Реєстратор: AMAZO-ZFRA (ASN: 16509).
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
Analysis of c51691985319.ngrok-free.app indicates this domain was a transient phishing endpoint hosted via ngrok's free tunneling service. As of July 25, 2026, the domain resolves to 3.125.102.39 (AS16509, Amazon.com, Inc., DE) and presents a 404 HTTP status, suggesting the malicious content has been removed or the tunnel terminated. The page title, 'ERR_NGROK_6024 - You are about to visit c51691985319.ngrok-free.app, served by 185.150.25.240,' is consistent with ngrok's default interstitial warning, which appears when users attempt to access a free subdomain. This warning does not confirm malicious intent but signals the domain was publicly exposed via ngrok's infrastructure, a common tactic for phishing campaigns due to its ephemeral nature and lack of persistent registration requirements. Six of 95 security vendors on VirusTotal flagged the domain, though the specific detection logic is not publicly available.
The domain appears on at least one security blocklist, and PhishDestroy has explicitly blocked it. The SSL certificate, issued by Let's Encrypt (serial E7), provides no additional attribution, as free certificates are standard for ngrok-hosted endpoints. No brand, kit, or specific scam type is identified in the available data; the domain is classified as generic phishing based on blocklist inclusion and vendor detections. The hosting IP (3.125.102.39) is part of Amazon's cloud infrastructure, which is frequently leveraged for short-lived malicious endpoints due to its scalability and low cost. Defenders should treat this domain as compromised infrastructure.
While the endpoint is currently offline, ngrok-free.app subdomains are often recycled or reused for new campaigns. Network-level blocking of the domain and associated IP (3.125.102.39) is recommended, alongside monitoring for new subdomains under ngrok-free.app with similar patterns (e.g., randomized alphanumeric strings).
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Аналіз VirusTotal
Архівні докази
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога