coibese-io-tn-help[.]square[.]site
“Nur einen Moment…”
coibese-io-tn-help.square.site — Контент недоступний (HTTP 404). Зведення доказів: VirusTotal 16/95 (ChainPatrol, alphaMountain.ai, BitDefender, Certego, CRDF); Google Safe Browsing flagged; PhishDestroy score 98/100. Реєстратор: MarkMonitor.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
The domain coibese-io-tn-help.square.site is flagged by multiple security sources as a high‑risk phishing infrastructure. It appears on one public blocklist and is actively blocked by PhishDestroy, indicating that defensive teams have already taken remediation steps. DNS resolution points to IP address 74.115.51.5, which is allocated to AS27647 (Weebly, Inc.) in the United States. The hosting environment is built on Amazon Web Services and further protected by Cloudflare, a combination frequently used to provide resilience and concealment for malicious actors.
The domain was registered on February 5, 2019 through MarkMonitor, Inc., a registrar commonly associated with legitimate brand protection services, which may be leveraged to lend credibility to the malicious site. The SSL certificate is issued by Let’s Encrypt (identifier E7), providing HTTPS encryption without any indication of a trusted commercial certificate authority. A HTTP request to the site returns a 404 status, and the only visible page title is “Nur einen Moment…”, a German phrase meaning “Just a moment…”, suggesting that the content was either removed or never served before the takedown. Google Safe Browsing classifies the site under social engineering, reinforcing the phishing assessment.
VirusTotal scans report 16 detections out of 95 security vendors, confirming that the domain is recognized by a substantial portion of the security community as malicious. Because the site is currently offline, immediate impact is limited, but the infrastructure—particularly the shared IP and the AWS/Cloudflare stack—remains reusable for future campaigns. Defenders should continue to block the domain and its resolved IP, monitor the associated nameservers (ns-1248.awsdns-28.org, ns-1816.awsdns-35.co.uk, ns-311.awsdns-38.com, ns-810.awsdns) for any new sub‑domains, and update URL filtering and intrusion detection signatures to capture any re‑use of this hosting profile.
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Збережений знімок
Аналітика доменів
Технічні деталіDNS, SAN-адреси SSL, мітки часу
ICANN OVERSIGHT
Registration: square.site
Акредитація та контекст RAA
Акредитація та контекст RAA
Registrar accreditation and DNS abuse obligations
For the registrable domain square.site behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Технології · 2 identified
Cloud computing platform offering compute, storage, and networking services.
Web infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comАналіз VirusTotal
Архівні докази
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога