h1[.]olux[.]click
“Site is created successfully!”
Зведення доказів
This domain, h1.olux.click, is assessed as a high-risk credential harvesting phishing site. Analysis indicates it was actively used to deceive users into submitting sensitive login information, likely through spoofed authentication portals or fraudulent account verification pages. The infrastructure exhibits multiple red flags consistent with phishing operations, including the absence of encryption and rapid deployment following domain registration. Infrastructure analysis reveals the following technical indicators: the domain was registered on August 30, 2025, through Sav.com, LLC, and resolves to the IP address 178.16.53.103, hosted on AS202412 (Omegatech LTD) in the Netherlands. Security vendors flagged the domain with 17 detections out of 95 on VirusTotal, while Google Safe Browsing classified it as phishing. The page title 'Site is created successfully!' suggests automated or template-based deployment, a common tactic in phishing campaigns. The domain appears on at least one security blocklist and was subsequently taken offline, though residual risk may persist for users who interacted with it prior to deactivation. Mitigation measures should focus on credential security and infrastructure hardening. Organizations should immediately block the domain and its associated IP (178.16.53.103) at the network level, including DNS and proxy filters. Users who may have entered credentials on this site should reset passwords for all accounts where the same credentials were reused, prioritizing email, financial, and administrative access. Multi-factor authentication (MFA) should be enforced for all critical accounts to mitigate the impact of stolen credentials. Security teams should monitor for follow-up phishing attempts using similar domains or IPs within the same hosting provider (AS202412), as threat actors often reuse infrastructure across campaigns.
Data Coverage
Розвіддані з мережевої безпеки
Процес реагування на загрози Pipeline
Перевірка за блок-листами
10 зовнішніх джерел під наглядом · знімок від 13.08.2026
Хронологія виявлення
-
Cloudflare Radar
Сканування Cloudflare Radar збережено · Відкрити сканування
Збережений знімок
Аналітика доменів
Технічні подробиціDNS, імена TLS і часові мітки
ICANN OVERSIGHT
Registration: olux.click
Акредитація та контекст RAA
Акредитація та контекст RAA
Registrar accreditation and DNS abuse obligations
For the registrable domain olux.click behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Аналіз VirusTotal
Аналіз продуктивності сайту
Google PageSpeed Insights — mobile performance audit of h1.olux.click · checked Mar 1, 2026
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога