hofaso[.]do
“.”
Зведення доказів
The domain hofaso.do was registered on 21 February 2026 and is presently taken offline. DNS resolution points to the IPv4 address 185.231.33.130, which is announced by AS211720 belonging to Datashield, Inc. and geolocated to South Carolina, United States. The host presents an SSL certificate identified as R12, indicating the use of a short‑lived or self‑signed certificate typical of malicious infrastructure. Reputation services have flagged the domain: three of ninety‑three VirusTotal scanners reported detections, and the site is listed on a single external blocklist.
Additionally, the PhishDestroy feed has actively blocked the domain. The page title returned by HTTP queries is a single period (“.”), providing no insight into the intended impersonated brand or lure technique. No public evidence of the landing page content, credential‑capture forms, or redirect behavior is available, and the site does not appear to be serving active traffic at the time of analysis. Given the limited but concrete indicators—recent registration, dedicated IP under a known hosting ASN, low‑level TLS certificate, and multi‑vendor detection—it is prudent for defensive teams to treat hofaso.do as a malicious phishing vector until further remediation.
Organizations should add the domain and its resolving IP address to network‑level deny lists, enforce DNS filtering that incorporates the observed blocklist entry, and ensure that web‑proxy and email security gateways reference the PhishDestroy feed. Continuous monitoring of the IP space owned by Datashield, Inc. may reveal additional related artifacts. Because the site is offline, active response options such as sinkholing are not applicable, but threat‑intel correlation with other observed campaigns that share the same ASN or certificate profile could surface broader attribution.
Data Coverage
Процес реагування на загрози Pipeline
Перевірка за блок-листами
10 зовнішніх джерел під наглядом · знімок від 12.08.2026
Аналіз VirusTotal
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога