gwem76x[.]life
“GET-X”
gwem76x.life — Неперевірений. Зведення доказів: VirusTotal 10/91 (alphaMountain.ai, BitDefender, Chong Lua Dao, CyRadar, ESET); Spamhaus DBL_SPAM; PhishDestroy score 88/100. Реєстратор: URL Solutions.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
Analysis indicates that the domain gwem76x.life is actively flagged as a high-risk phishing site targeting credentials under the page title 'GET-X'. Registered on February 21, 2026, through URL Solutions, Inc., the domain resolves to the IP address 186.2.165.69, hosted by Iqweb LLC in the United Arab Emirates. Infrastructure analysis reveals the use of nameservers ns1.pananames.com through ns4.pananames.com, a pattern commonly observed in phishing campaigns leveraging bulk domain registration services. The domain is currently detected by 2 of 93 security vendors on a widely used scanning platform, with additional blocking by at least one dedicated anti-phishing system. The SSL certificate is classified as R11, a designation often associated with low-trust or automated certificate issuance, further reducing confidence in the domain's legitimacy. Technologies detected on the site include Node.js, Google Cloud, Vue.js, Nuxt.js, Nginx, Amazon Web Services, and reCAPTCHA, suggesting a moderately sophisticated infrastructure that may be used to evade basic detection mechanisms or simulate legitimacy. The HTTP status code 301 indicates a permanent redirect, though the destination remains unconfirmed. The domain appears on one security blocklist as of the report date. While the exact brand or service being impersonated is not explicitly identified in available data, the page title 'GET-X' may imply a focus on credential harvesting or account takeover attempts. Defenders are advised to treat this domain as malicious and implement blocking at the DNS or network level. Further investigation into associated IP ranges, certificate histories, and redirect chains is recommended to identify related infrastructure. Given the active status and high-risk classification, monitoring for new domains registered under the same nameservers or IP space may aid in preemptive mitigation.
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Збережений знімок
Аналітика доменів
Технічні деталіDNS, SAN-адреси SSL, мітки часу
ICANN OVERSIGHT
Акредитація та контекст RAA
Акредитація та контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Технології · 14 identified
JavaScript runtime built on Chrome V8 engine for server-side development.
Suite of cloud computing services running on Google infrastructure.
Progressive JavaScript framework for building user interfaces.
Hybrid Vue framework for server-side rendering and static sites.
High-performance HTTP server and reverse proxy, known for stability and low resource usage.
Cloud computing platform offering compute, storage, and networking services.
Google's bot-challenge service. On phishing sites, used to appear legitimate and filter out automated scanners.
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
Tag management system for deploying marketing and analytics tags.
tagmanager.google.comContent delivery network built on Google global edge infrastructure.
Web analytics service tracking website traffic and user behavior.
marketingplatform.google.comAmazon Web Services CDN for low-latency content delivery.
Third major version of HTTP protocol, built on QUIC for faster, more reliable connections.
Аналіз VirusTotal
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога