guiadecarrosorcamento[.]com
“- Consultoria Automotiva Online”
guiadecarrosorcamento.com — Неперевірений. Уособлення бренду: Celer. Зведення доказів: VirusTotal 6/94 (alphaMountain.ai, Chong Lua Dao, CyRadar, Fortinet, Gridinsoft); URLQuery 1 alert; Spamhaus DBL_PHISH; PhishDestroy score 72/100. Реєстратор: NiceNIC.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
This domain is classified under an elevated risk level for credential harvesting phishing, a targeted attack vector designed to steal authentication credentials through fraudulent login portals. Analysis indicates the infrastructure was engineered to mimic legitimate automotive service platforms, increasing the likelihood of successful social engineering against targeted users. Infrastructure analysis reveals the domain was registered through NICENIC INTERNATIONAL GROUP CO., LIMITED on March 27, 2026, and resolved to IP address 188.114.96.3. Security telemetry shows 6 out of 95 detection engines on VirusTotal flagged the domain as malicious, while it appears on one security blocklist. AlienVault OTX records the domain in a single threat intelligence pulse, and PhishDestroy has implemented active blocking measures against it. Organizations should implement the following mitigation measures: (1) Add the domain and associated IP 188.114.96.3 to network-level blocklists across firewalls, proxies, and DNS resolvers; (2) Deploy retroactive scanning of endpoint logs for connections to the domain or IP during its active period; (3) Conduct user awareness training focused on credential harvesting tactics, particularly those impersonating service portals; (4) Monitor for secondary domains registered through the same registrar (NICENIC INTERNATIONAL GROUP CO., LIMITED) with similar naming patterns; (5) Implement multi-factor authentication (MFA) as a compensating control to mitigate the impact of credential theft from phishing attacks.
Розвіддані з мережевої безпеки Registrar context
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DNS4EU | guiadecarrosorcamento.com |
malicious | Sinkholed |
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Збережений знімок
Аналітика доменів
Технічні деталіDNS, SAN-адреси SSL, мітки часу
ICANN OVERSIGHT
Акредитація та контекст RAA
Акредитація та контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Latest Classified Outcome 2026-08-13 03:03:29 UTC
Аналіз VirusTotal
Докази та зовнішні звіти
PD-20260328-DD0DBA Recipient: abuse@nicenic.net, abuse@verisign-grs.com, compliance@icann.org Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога