migrate-aitech[.]app
Збережене виявлення
Виявлено маскування
- Тип маскування
content_divergence- Оцінка маскування
- 1/6
- Причина
- cloudflare_ban: raw=cf_phishing_block; http=403; via=https_proxy; server=cloudflare; provider_error=cloudflare_phishing_interstitial
The domain migrate-aitech.app was registered on May 09 2026 through NICENIC INTERNATIONAL GROUP CO., LIMITED. It is hosted behind Cloudflare’s network (nameservers leif.ns.cloudflare.com and martha.ns.cloudflare.com) and resolves to the IP address 188.114.97.3, which is geolocated to Canada. The site currently returns HTTP 403 responses and presents a Let’s Encrypt certificate (issuer E8).
Multiple security feeds have flagged the domain. PhishDestroy has already added it to its blocklist, and AlienVault OTX lists it in one threat‑intelligence pulse. VirusTotal reports three of ninety‑five scanning engines flagging the domain as malicious, and Gridinsoft assigns it a trust score of 0 out of 100. The domain also appears on a separate public blocklist, reinforcing the consensus that it is being used for malicious activity.
The available evidence points to a generic phishing operation, consistent with the threat type classification. The presence of a valid TLS certificate and a 403 status page suggests the operators are attempting to obscure the underlying malicious payload while maintaining a legitimate‑looking HTTPS endpoint. However, no specific phishing kit, targeted brand, or payload details have been observed in the current intelligence, leaving the exact content of the lure uncertain.
Defenders should immediately block traffic to migrate-aitech.app and its resolving IP 188.114.97.3 at the perimeter. Continuous monitoring of DNS queries for this domain and related Cloudflare‑hosted IP ranges is advised to detect any resurgence. Adding the domain to internal blacklists, updating SIEM correlation rules with the observed indicators, and considering sinkholing the IP can reduce exposure while further investigation continues.
Розвіддані з мережевої безпеки Registrar context
Процес реагування на загрози Pipeline
Перевірка за блок-листами
Джерел: 10 · синхронізовано 09.08.2026
Збережені докази результату
Результат і атрибуція блокування
- Результат
blocked- Причина
cloudflare_antiphishing- Учасник
- Cloudflare
- Механізм
phishing_interstitial- Упевненість
- 95%
Оцінка часу недоступності
Діапазон похибки: ±3.88 h Точність часу:high Хронологія виявлення
Збережені спостереження у хронологічному порядку.
-
Збережене спостереження
Збережене спостереження: alive → dead
-
Збережене спостереження
Збережене спостереження: dead → alive
Аналітика доменів
Технічні подробиціDNS, SAN-адреси SSL, мітки часу
ICANN OVERSIGHT
Акредитація та контекст RAA
Акредитація та контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Аналіз VirusTotal
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога