getdiscount[.]vip
“getdiscount.vip”
Зведення доказів
This domain, getdiscount.vip, is identified as a credential theft phishing infrastructure designed to harvest login credentials through deceptive offers and fraudulent login portals. Analysis indicates the domain was structured to mimic legitimate discount or promotional services, tricking users into entering sensitive account details under false pretenses. The threat primarily targets individuals seeking financial incentives, leveraging social engineering tactics to bypass initial user skepticism. Evidence supporting this assessment includes detection by 19 out of 95 security vendors on VirusTotal, indicating broad consensus on its malicious nature. The domain was registered on February 21, 2026, through Gname.com Pte. Ltd., and resolved to the IP address 47.77.216.153, hosted under AS45102 (Alibaba (US) Technology Co., Ltd.). It appears on one security blocklist, and its SSL certificate was issued under the identifier PhishDestroy / botadmin.destroy.tools, further linking it to known phishing toolkits. The domain has since been taken offline, but residual risk remains for users who may have interacted with it prior to deactivation. Users who visited getdiscount.vip or entered credentials on any associated pages should immediately reset passwords for all accounts accessed from the same device or network. Enable multi-factor authentication (MFA) where available to mitigate unauthorized access. Monitor financial and personal accounts for suspicious activity, as stolen credentials may be used in follow-up attacks. If the domain was accessed via a corporate or shared device, notify the relevant IT or security team to conduct a forensic review. Exercise caution with unsolicited promotional links, particularly those offering unrealistic discounts or requiring immediate login.
Data Coverage
Розвіддані з мережевої безпеки
Процес реагування на загрози Pipeline
Перевірка за блок-листами
10 зовнішніх джерел під наглядом · знімок від 11.08.2026
Хронологія виявлення
-
Cloudflare Radar
Сканування Cloudflare Radar збережено · Відкрити сканування
-
VirusTotal
19 → 20
Аналітика доменів
Технічні подробиціDNS, імена TLS і часові мітки
ICANN OVERSIGHT
Акредитація та контекст RAA
Акредитація та контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Аналіз VirusTotal
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога