eggywall[.]st
Перевірка домену eggywall.st на фішинг і безпеку
“EggyWall - Website DDoS Protection”
eggywall.st — Контент недоступний (HTTP 502). Зведення доказів: VirusTotal 2 detections (engine total unavailable) (Seclookup, Sophos); URLQuery 2 alerts; PhishDestroy score 62/100. Реєстратор: ST Registry.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
Analysis of eggywall.st indicates that the domain is being used for a generic phishing campaign targeting users who might be seeking DDoS protection services. The site is registered through ST Registry and was created on March 06, 2026. Technical fingerprints reveal an Ubuntu operating system running Apache HTTP Server behind a Cloudflare front end, with client‑side cryptographic libraries crypto‑js and cdnjs present in the page assets. The domain resolves to the IPv4 address 151.247.193.142, which maps to a French location and is announced by AS399486 (12651980 CANADA INC.).
The TLS certificate is issued by Let’s Encrypt (E7), confirming that the site employed a valid, publicly trusted certificate at the time of observation. DNS resolution is handled by nameservers ns1.eggywall.cc and ns2.eggywall.cc, suggesting that the attacker controls a separate second‑level domain for name service. Security telemetry shows that two of ninety‑five VirusTotal scanners flagged the domain, and it appears on a single external blocklist, with PhishDestroy already marking it as blocked. The page title returned by the server is "EggyWall - Website DDoS Protection," which aligns with the advertised service claim.
Current operational status is offline, indicating that the infrastructure may have been taken down or is temporarily inaccessible. Defenders should continue to monitor the IP address and associated ASN for any re‑activation, enforce blocks on the domain and its IP at perimeter devices, and add the domain to internal phishing and URL filtering lists. Given the presence of Cloudflare, any future resurrection could leverage the same edge service, so threat‑intel teams should watch for new DNS records under the same nameservers or similar certificate issuances. Continuous re‑scanning with multi‑vendor engines is advised to capture any changes in detection posture.
Розвіддані з мережевої безпеки
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Технології · 5 identified
Most widely used open-source HTTP server software.
Web infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comАналіз VirusTotal
Архівні докази
Докази та зовнішні звіти
PD-20260306-1B9298 Recipient: report@abuseradar.com Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога