MALICIOUS — CRITICAL
manuelperujo[.]com
The domain manuelperujo.com is currently active and has been identified as a generic phishing infrastructure.
- VirusTotal
- 7/94
- Blocklists
- No stored match
- Доступність
- Останній відомий активний · HTTP 301
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
manuelperujo.com — Останній відомий активний (HTTP 301). Тип шахрайства: Generic Phishing. Зведення доказів: VirusTotal 7/94 (alphaMountain.ai, Cluster25, CRDF, CyRadar, Gridinsoft); URLQuery 4 alerts; PhishDestroy score 81/100. Реєстратор: DonDominio (SCIP).
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
Evidence Analysis
The domain manuelperujo.com is currently active and has been identified as a generic phishing infrastructure. The site was registered on December 21, 2017 through DonDominio (SCIP) and is hosted on an Apache HTTP Server that enforces HSTS. Traffic to the domain resolves to IP address 31.214.178.78, which is registered to Soluciones Corporativas IP, SL in Spain. The SSL certificate presented is issued to Soluciones Corporativas IP SL and signed by the Don Dominio RSA DV SSL CA 2, indicating a legitimate‑looking TLS configuration.
HTTP requests receive a 301 redirect response, and the page title returned by the server is "Manuel Perujo - illustrator / 2D animator". The domain is listed on one security blocklist and has been explicitly blocked by the PhishDestroy service. VirusTotal analysis shows that 7 of 94 security vendors have flagged the domain, reinforcing the suspicion of malicious use. Additional indicators include a Gridinsoft trust score of 0 / 100, MX record pointing to mx01.dondominio.com (priority 10), and nameservers ns2.dondominio.com and ns7.dondominio.com.
While the page content has not been publicly dissected, the combination of a recent redirect, a professional‑grade certificate, and multiple vendor detections suggests the site is being leveraged for credential harvesting or related phishing tactics. Defenders should block the domain at perimeter defenses, monitor DNS queries for the associated IP and MX host, and consider adding the address to internal blocklists. Continuous re‑scanning on VirusTotal and similar platforms is advised to capture any escalation in detection rates.
Обсяг даних12 recorded checks
Розвіддані з мережевої безпеки
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Hagezi Threat Feed | manuelperujo.com |
malicious | Sinkholed |
| DNS4EU | manuelperujo.com |
malicious | Sinkholed |
| Hagezi Threat Feed | www.manuelperujo.com |
malicious | Sinkholed |
| DNS4EU | www.manuelperujo.com |
malicious | Sinkholed |
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Збережений знімок
Аналітика доменів
Технічні деталіDNS, SAN-адреси SSL, мітки часу
ICANN OVERSIGHT
Акредитація та контекст RAA
Акредитація та контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Технології · 3 identified
Most widely used open-source HTTP server software.
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
Web analytics service tracking website traffic and user behavior.
marketingplatform.google.comАналіз VirusTotal
Аналіз продуктивності сайту
Google PageSpeed Insights — mobile performance audit of manuelperujo.com · checked Mar 22, 2026
Докази та зовнішні звітиIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.