expressdgl[.]pics
Перевірка домену expressdgl.pics на фішинг і безпеку
“Atto - Time Clock & Scheduling - Apps on Google Play”
expressdgl.pics — Прикритий · доступний (HTTP 302). Уособлення бренду: Google; Тип шахрайства: Brand Impersonation. Зведення доказів: VirusTotal 5/94 (alphaMountain.ai, CRDF, Forcepoint ThreatSeeker, Gridinsoft, SOCRadar); cloaking observed; PhishDestroy score 100/100. Реєстратор: Dynadot.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
expressdgl.pics is currently active and classified as a high‑risk Google brand‑impersonation campaign. The domain was registered on 2026‑04‑09 through Dynadot LLC and is hosted on Cloudflare infrastructure, using the nameservers byron.ns.cloudflare.com and elle.ns.cloudflare.com. DNS resolution points to IP 188.114.97.3, which is listed as a Cloudflare location in Canada. HTTP requests receive a 302 redirect and the site presents a TLS certificate issued by Let’s Encrypt (identifier E8). VirusTotal records indicate that 5 of 94 scanned engines flag the domain, and AlienVault OTX references it in 22 separate threat‑intel pulses. The Gridinsoft trust score is 0 / 100, and the domain appears on a single external blocklist. PhishDestroy has already added it to its block list. The only observed page title is “Atto – Time Clock & Scheduling – Apps on Google Play”, suggesting the site may be leveraging a legitimate‑looking Google Play listing to lure victims, though the exact page content has not been examined. Defenders should block both the domain and its resolving IP at perimeter and DNS layers, monitor for related redirects, and consider adding the host to threat‑intel feeds. Ongoing observation is recommended to capture any payloads or credential‑harvesting forms that may be deployed behind the redirect.
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Збережений знімок
Аналітика доменів
Технічні деталіDNS, SAN-адреси SSL, мітки часу
ICANN OVERSIGHT
Акредитація та контекст RAA
Акредитація та контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Аналіз VirusTotal
Аналіз продуктивності сайту
Google PageSpeed Insights — mobile performance audit of expressdgl.pics · checked Jul 12, 2026
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога