go-debito[.]com
Перевірка домену go-debito.com на фішинг і безпеку
“Consultar Veículo - IPVA, Multas e CRLV - Expresso”
go-debito.com — Контент недоступний (HTTP 502). Зведення доказів: VirusTotal 5/94 (alphaMountain.ai, CyRadar, Fortinet, Gridinsoft, SOCRadar); Spamhaus DBL_PHISH; PhishDestroy score 65/100. Реєстратор: NiceNIC.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
Evidence Analysis
This domain, go-debito.com, is flagged as a generic phishing site designed to harvest user credentials, likely targeting financial or payment-related services. Analysis indicates no direct association with a specific brand or known phishing kit, though its infrastructure aligns with credential theft campaigns. The domain exhibits characteristics typical of short-lived phishing operations, including rapid deployment and low trust scores across security platforms. Infrastructure analysis reveals concrete technical indicators: the domain is registered through NICENIC INTERNATIONAL GROUP CO., LIMITED, with a creation date of March 27, 2026—an anomalous future timestamp suggesting potential domain spoofing or registry manipulation. It resolves to the IP address 188.114.96.3, a host with a history of abuse in phishing campaigns. Security vendor detections on VirusTotal stand at 5/95, while the Gridinsoft trust score is 0/100, confirming its malicious classification. The domain appears on one active security blocklist and was previously identified in a single threat intelligence pulse on AlienVault OTX. Currently, go-debito.com is reported as offline, likely due to takedown efforts or infrastructure suspension. However, residual risk persists due to the domain's presence on blocklists and its historical resolution to a known malicious IP. Users who accessed the site prior to its takedown should assume credential exposure and initiate password resets, particularly for financial accounts. Organizations are advised to monitor network logs for connections to 188.114.96.3 and implement DNS-based blocking for the domain to prevent potential re-emergence. The anomalous registration date warrants further investigation into registrar abuse patterns.
Обсяг даних12 recorded checks
Розвіддані з мережевої безпеки Registrar context
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Збережений знімок
Аналітика доменів
Технічні деталіDNS, SAN-адреси SSL, мітки часу
ICANN OVERSIGHT
Акредитація та контекст RAA
Акредитація та контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Latest Classified Outcome 2026-08-09 03:55:39 UTC
Аналіз VirusTotal
Докази та зовнішні звітиIndependent lookups and source reports
PD-20260327-1F6148 Recipient: abuse@nicenic.net, abuse@verisign-grs.com, compliance@icann.org Victim safety and official reportingImmediate actions and verified reporting channels
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.