Перейти до звіту про безпеку
⚠️
Цей домен було позначено як шкідливий
Системи безпеки повідомляють про виявлення: 6. Будьте дуже обережні — не вводьте облікові дані чи особисту інформацію.
Безпека домену та аналіз загроз

iranxfin[.]online

“سقوط آزاد — Freefall”

Загрозливий вердикт Критичний 78/100 оцінка доказів
Доступність Неперевірений Поточна доступність не перевірена
Виявлення VirusTotal: 6/91
22.07.2026
Огляд звіту

iranxfin.online — Неперевірений. Зведення доказів: VirusTotal 6/91 (alphaMountain.ai, CRDF, ESET, Forcepoint ThreatSeeker, Gridinsoft); PhishDestroy score 78/100. Реєстратор: Namecheap.

Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.

Зведення доказів
КРИТИЧНИЙ
Посилання
36D3E987
Оцінка
78/100

Analysis as of July 22, 2026 indicates that the domain iranxfin.online was registered on July 09, 2026 through Namecheap Inc. The authoritative name servers are dns1.registrar-servers.com and dns2.registrar-servers.com, and DNS resolution points to the IPv4 address 35.159.10.46. The domain is currently active and has been observed on a single security blocklist. The anti‑phishing service PhishDestroy has explicitly blocked the domain, and VirusTotal reports that four of ninety‑five scanned security vendors have flagged the host as malicious. No additional public reputation services, Safe Browsing checks, or Open Threat Exchange (OTX) entries were supplied in the intelligence set.

The limited detection footprint suggests that the infrastructure is either newly deployed or employing evasion techniques to avoid broader cataloging. The hosting provider or autonomous system for the IP address has not been disclosed, and no SSL certificate details, HTTP response codes, or page title information are available, leaving the surface‑web characteristics of the site unverified. Defenders should add iranxfin.online to inbound and outbound filtering rules, monitor DNS queries for the associated name servers, and enforce blocklist updates that include the domain.

Given the presence on a dedicated phishing blocklist and the multiple vendor detections, it is prudent to treat any communications referencing this domain as malicious. Continuous observation of the IP address 35.159.10.46 for changes in hosting, reputation, or new payload delivery is recommended, as is periodic re‑query of VirusTotal and other analysis platforms to capture any escalation in detection counts. Organizations employing email security gateways should explicitly deny URLs that resolve to this domain, and SOC teams should correlate any login or credential submission attempts to iranxfin.online with potential credential harvesting campaigns.

VirusTotal
VirusTotal
6 det.
URLScan
URLScan
Сертифікат TLS
Let's Encrypt
Вік
1 mo New
Зафіксований статус
Неперевірений
PhishDestroy
DestroyList
У списку
Обсяг даних VirusTotal 6 / 91 URLQuery не перевірено PhishStats не перевірено OTX no community references CF Radar scan completed URLScan capture збережений звіт URLScan verdict Аналіз завершено Блокування DNS не перевірено TLS valid certificate, 76d WHOIS 1 mo old Знімок екрана 2 captures · 2 sources Ланцюжок перенаправлень не досліджено

Процес реагування на загрози Pipeline

Відкриття
Checks
Reports
Доступність
10/12

Статус у публічних блоклистах

Збережений знімок

Заголовок сторінки
سقوط آزاد — Freefall
Сертифікат TLS
Valid transport encryption · Виданий Let's Encrypt · valid for 76 days

Аналітика доменів

Домен
URLScan Verdict Аналіз завершено score 0 report ↗
Сервер / ASN openresty/1.31.1.1 · AS16509 Amazon.com, Inc.
Репутація IP abuse score 0/100 0 reports checked 23.07.2026
Реєстратор Namecheap SE(SE)
IP-адреса 35.159.10.46 DE
ГеолокаціяDE Frankfurt am Main, DE
МережаAS16509 · AWS EC2 (eu-central-1)
Зворотний пошук IPviewdns.info → rapiddns.io →
РеєстраціяСтворено 09.07.2026 (38d · New) Expires 09.07.2027
Технічні деталіDNS, SAN-адреси SSL, мітки часу
Вперше виявлено22.07.2026
DOM Analysisanalyzed 23.07.2026score 78/100
IoC Extractionscanned 29.07.20260 wallet · 0 Telegram IoCs
Submitted URLhttps://iranxfin.online/
Сервери іменdns1.registrar-servers.comdns2.registrar-servers.com
MX Records10 eforward1.registrar-servers.com 10 eforward2.registrar-servers.com 10 eforward3.registrar-servers.com 15 eforward4.registrar-servers.com 20 eforward5.registrar-servers.com
TLS Fingerprint
TLS Observationvalid from 09.07.2026scanned 23.07.2026
ICANN OVERSIGHT

Акредитація та контекст RAA

Registrar accreditation and DNS abuse obligations

For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.

Accreditation is a contract, not a safety certification.

RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.

Accountability draft Нічого не надсилається автоматично.
Технології · 2 identified
Nginx
Web servers Reverse proxies

Nginx is a web server that can also be used as a reverse proxy, load balancer, mail proxy and HTTP cache.

nginx.org 100% впевненості
OpenResty
Web servers

OpenResty is a web platform based on nginx which can run Lua scripts using its LuaJIT engine.

openresty.org 100% впевненості
Detected via Cloudflare Radar · Wappalyzer engine
Поскаржитися на цей домен Надішліть докази та допоможіть захистити інших

Аналіз VirusTotal

6 / 91 постачальників безпеки позначили цей домен
View on VT
Last analyzed Previous stored snapshot: 6 detections
alphaMountain.ai
CRDF
ESET
Forcepoint ThreatSeeker
Gridinsoft
SOCRadar

Архівні докази

Wayback Machine Snapshot
Для перегляду доказів доступний історичний знімок
View Archive
Аналіз продуктивності сайту

Google PageSpeed Insights — mobile performance audit of iranxfin.online · checked Jul 22, 2026

85
Needs Work
Performance
FCP
3.36s
First Contentful Paint
LCP
3.36s
Largest Contentful Paint
CLS
0.007
Cumulative Layout Shift
TBT
0ms
Total Blocking Time
SI
3.36s
Speed Index
Powered by Google PageSpeed Insights · Mobile strategy · Scores: 90-100 Good 50-89 Needs Work 0-49 Poor

Докази та зовнішні звіти

Чи вплинув на вас цей сайт?

If credentials were compromised, report immediately. Do not engage with recovery scammers.

Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.

Європол
Знайдіть офіційний канал звітності для вашої країни ЄС
National police directory
Остерігайтеся шахраїв, які обіцяють повернути втрачені кошти! Злочинці можуть знову зв’язатися з жертвами, видаючи себе за слідчих, адвокатів або агентів із відновлення. Не сплачуйте авансових зборів і не діліться обліковими даними. Дізнайтеся більше про шахрайство у сфері відшкодування збитків →

Зверніться до місцевих органів влади

Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.

Довідник 97 країн
Чернетка за допомогою штучного інтелекту — деталі інциденту обробляються постачальником штучного інтелекту Перегляньте та подайте його самостійно

Перевірити будь-який домен

Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування

Сканувати зараз

Повідомити про фішинг

Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту

Повідомити

Потокова стрічка про загрози

Останні звіти про фішинг і помічені зміни доступності

Відстежувати

Будьте в курсі подій, дбайте про свою безпеку

Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога

Потокова стрічка про загрози Оскаржити це оголошення
HTML · IFRAME

Вбудувати цей звіт

Поділіться цією інформацією про загрози на своєму веб-сайті або в блозі

embed.html
<iframe
  src="https://phishdestroy.io/uk/embed/domain/iranxfin.online"
  title="PhishDestroy threat report for iranxfin.online"
  width="100%" height="320"
  loading="lazy"
  referrerpolicy="no-referrer"
  sandbox="allow-same-origin allow-popups allow-popups-to-escape-sandbox"
  style="border:0;border-radius:12px;max-width:100%"
></iframe>

Дуже щирий лист-подяка

Генератор сатиричних чернеток

Одержувач
Контекст зборів

Це сатирична чернетка. Суми зборів є оцінками; ми не стверджуємо, що вони точно стосуються цього домену.