gqtpzsrdeics[.]top
“welcome!!”
gqtpzsrdeics.top — Неперевірений. Тип шахрайства: Generic Phishing. Зведення доказів: VirusTotal 18/91 (Criminal IP, alphaMountain.ai, Cluster25, CRDF, ESET); CF Radar malicious; PhishDestroy score 98/100. Реєстратор: Spaceship.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
Analysis conducted on July 19, 2026, identifies gqtpzsrdeics.top as an active phishing domain exhibiting high-risk characteristics. The domain presents a page titled 'welcome!!', a generic but commonly observed indicator in credential-harvesting or initial-access phishing schemes. Infrastructure analysis reveals the domain is proxied through Cloudflare, resolving to IP address 172.67.220.126, which is geolocated in Canada under Cloudflare, Inc. Nameservers colin.ns.cloudflare.com and jewel.ns.cloudflare.com further confirm Cloudflare’s role in hosting the malicious infrastructure. The domain is registered through Spaceship, Inc., and uses an SSL certificate issued by Google Trust Services (WE1), a configuration frequently exploited to lend false legitimacy to phishing pages. Current detection data shows the domain is flagged by 18 of 91 security vendors on VirusTotal, indicating broad consensus among threat intelligence providers regarding its malicious nature. Additionally, the domain appears on one security blocklist and has been documented in three AlienVault OTX threat intelligence pulses, suggesting persistent or recurring phishing activity. Defenders should treat this domain as hostile. The HTTP 200 status confirms the page remains accessible, and the lack of takedown or sinkholing indicates continued operational use. While the exact brand or service being impersonated is not specified in available data, the 'welcome!!' page title and generic phishing classification suggest a likely attempt to harvest user credentials or distribute malware. Network-level blocking is recommended, alongside monitoring for connections to 172.67.220.126 or related Cloudflare-proxied infrastructure. Further analysis of page content or captured payloads may clarify the specific phishing campaign, but current evidence alone justifies immediate defensive action.
Розвіддані з мережевої безпеки
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Аналітика доменів
Технічні деталіDNS, SAN-адреси SSL, мітки часу
ICANN OVERSIGHT
Акредитація та контекст RAA
Акредитація та контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Технології · 4 identified
HTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org 100% впевненостіCloudflare Browser Insights is a tool that measures the performance of websites from the perspective of users.
www.cloudflare.com 100% впевненостіCloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com 100% впевненостіHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100% впевненостіАналіз VirusTotal
Аналіз продуктивності сайту
Google PageSpeed Insights — mobile performance audit of gqtpzsrdeics.top · checked Jul 20, 2026
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога