lumstarmgmt[.]click
“Welcome to All Celebrities Bookings”
lumstarmgmt.click — Неперевірений. Уособлення бренду: Foundation; Тип шахрайства: Brand Impersonation. Зведення доказів: VirusTotal 5/91 (alphaMountain.ai, CRDF, Forcepoint ThreatSeeker, Gridinsoft, LevelBlue); PhishDestroy score 65/100. Реєстратор: OwnRegistrar.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
The domain lumstarmgmt.click is a confirmed phishing site engaged in brand impersonation, specifically targeting users by falsely representing itself as associated with 'foundation'. This site was designed to deceive visitors through fraudulent login or credential harvesting pages, posing an elevated risk of identity theft or financial fraud. As of the latest verification, lumstarmgmt.click has been taken offline, though it previously operated as an active scam.
Technical analysis reveals that lumstarmgmt.click was flagged by 1 of 95 VirusTotal security vendors, including Seclookup, and appeared on 1 security blocklist (PhishDestroy). The domain was registered through OwnRegistrar, Inc. on August 11, 2025, and resolved to the IP address 163.61.188.89, hosted on AS153568 (NEW DHAKA HARDWARE) in the US. No SSL certificate was issued for the site, and its nameservers included dns1.ecositespace.com, dns2.ecositespace.com, vip1.cupisweb.com, and vip2.cupisweb.com. The observed page title was 'Welcome to All Celebrities Bookings', which did not align with the impersonated brand, further indicating its fraudulent nature.
Individuals who interacted with lumstarmgmt.click should immediately change any passwords entered on the site and enable two-factor authentication (2FA) on all sensitive accounts. Monitor financial statements and credit reports for unauthorized activity, as stolen credentials may be used for further fraud. Report the domain to platforms such as Google Safe Browsing, the Federal Trade Commission (FTC), or local cybercrime units to aid in takedown efforts and prevent further victimization.
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Збережений знімок
Аналітика доменів
Технічні деталіDNS, SAN-адреси SSL, мітки часу
ICANN OVERSIGHT
Акредитація та контекст RAA
Акредитація та контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Аналіз VirusTotal
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога