immediatorisorsa-ia[.]net
immediatorisorsa-ia.net — Контент недоступний. Уособлення бренду: Genericcloudflare. Зведення доказів: VirusTotal 9/93 (alphaMountain.ai, CRDF, CyRadar, ESET, Forcepoint ThreatSeeker); URLScan malicious verdict; 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 77/100.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
This domain, immediatorisorsa-ia.net, is identified as a crypto drainer phishing site designed to compromise digital wallet credentials. Analysis indicates the infrastructure mimics legitimate cryptocurrency services, likely employing social engineering tactics to trick users into disclosing private keys or executing malicious transactions. No explicit brand impersonation is confirmed, but the domain naming convention suggests an attempt to appear associated with financial or resource-allocation platforms. Infrastructure analysis reveals the domain was registered on February 21, 2026, through NameCheap, Inc. It resolves to the IP address 188.114.96.3, hosted on AS13335 (Cloudflare, Inc.) with a United States geolocation. The domain is flagged by 9 out of 95 security vendors on VirusTotal, and appears on three distinct security blocklists, including entries from PhishDestroy, MetaMask, and SEAL. The SSL certificate is issued under the WE1 authority, a common but not exclusive indicator of phishing activity. Google Safe Browsing (GSB) does not currently list the domain, though this may reflect a lag in detection rather than absence of threat. As of the latest assessment, immediatorisorsa-ia.net has been taken offline, reducing immediate exposure risk. However, the domain remains registered and could be reactivated or repurposed. The registrar, NameCheap, has not publicly disclosed remediation actions, and the infrastructure (IP, ASN) may still host other malicious content. Users who interacted with the domain prior to takedown should assume credential compromise and initiate wallet migration, transaction reviews, and device scans. Ongoing monitoring of associated IPs and registrant patterns is recommended to detect potential resurgence.
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Криміналістичні дані
Аналіз VirusTotal
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога