fdh998[.]it
“fdh998.it | 522: Connection timed out”
Зведення доказів
The domain fdh998.it was observed hosting a generic phishing payload before being taken offline. The site returned the HTTP status 522 with the page title “fdh998.it | 522: Connection timed out”, indicating a Cloudflare‑originated timeout. Registration data shows the domain was created on 12 August 2025 and is registered through 1 Api GmbH. DNS resolution points to the IP address 104.21.86.23, which belongs to the Cloudflare network (ASN 13335) and is geolocated in the United States.
The domain uses Cloudflare’s DNS service, as reflected by the authoritative nameservers aria.ns.cloudflare.com and arturo.ns.cloudflare.com, and serves content over HTTP/3. TLS termination is performed by a certificate issued by Google Trust Services under the WE1 trust profile, confirming that the connection is encrypted but does not imply legitimacy of the hosted content. Reputation signals show that fdh998.it appears on a single security blocklist, specifically PhishDestroy, and two of the ninety‑five VirusTotal scanners flagged the domain as malicious. No further public threat‑intel platforms such as OTX or Safe Browsing have published indicators for this domain at the time of analysis.
The limited detection footprint suggests a short‑lived campaign that was possibly disrupted, as the current status is recorded as offline. Given the observed infrastructure, any residual artifacts such as the IP address 104.21.86.23 or the Cloudflare nameservers should be considered suspicious when encountered in correlation with phishing‑related traffic. Defenders are advised to continue monitoring for re‑use of the same registrar, nameserver set, or IP range, and to enforce blocklist updates that include fdh998.it. Additional investigation of the two security vendor detections may reveal payload characteristics, and threat‑hunting rules should be tuned to flag similar Cloudflare‑hosted domains that exhibit a 522 timeout response combined with recent registration dates.
Data Coverage
Розвіддані з мережевої безпеки
Процес реагування на загрози Pipeline
Перевірка за блок-листами
10 зовнішніх джерел під наглядом · знімок від 10.08.2026
Хронологія виявлення
-
Статус домену
Доступний → Недоступний
-
Cloudflare Radar
Сканування Cloudflare Radar збережено · Відкрити сканування
-
Статус домену
Недоступний → Доступний
Технології
Виявлено 2 технології з високою впевненістю
Аналіз VirusTotal
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога