hngk120[.]net
“404 Not Found”
hngk120.net — Неперевірений. Зведення доказів: VirusTotal 5/91 (alphaMountain.ai, Chong Lua Dao, CRDF, Gridinsoft, SOCRadar); PhishDestroy score 78/100. Реєстратор: Deep Water Domains.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
Analysis of hngk120.net shows the domain was registered on 21 February 2026 through Deep Water Domains LLC and is hosted on Cloudflare’s network (ASN 13335) with the IP address 188.114.97.3 located in the United States. The domain resolves to Cloudflare’s edge service and presents a valid SSL certificate issued by Google Trust Services under the WE1 certificate authority, indicating proper TLS termination. HTTP probing returns a 200 OK status, but the page title returned by the server is “404 Not Found”, suggesting the site is either serving a placeholder error page or intentionally obscuring its content.
The infrastructure uses Cloudflare’s HTTP/3 protocol, consistent with the observed technologies. Reputation checks reveal that two of ninety‑three VirusTotal scanners have flagged the domain, and the domain appears on three public blocklists, including PhishDestroy, MetaMask, and SEAL, all of which have it listed as active. No additional intelligence such as a targeted brand, specific phishing kit, or payload has been published, so the exact malicious intent remains unclear beyond the generic phishing classification.
Defenders should block network connections to 188.114.97.3 and add hngk120.net to URL filtering rules. Monitoring for future DNS or certificate changes is advised, as the presence of a legitimate TLS certificate can facilitate credential‑stealing pages. Organizations using cloud‑based email or web gateways should ensure that the domain is included in their threat intelligence feeds, and incident response teams should treat any communications originating from or referencing this domain as potentially malicious.
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Збережений знімок
Аналітика доменів
Технічні деталіDNS, SAN-адреси SSL, мітки часу
ICANN OVERSIGHT
Акредитація та контекст RAA
Акредитація та контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Технології · 2 identified
Web infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
Аналіз VirusTotal
Архівні докази
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога