ns[.]altintas-goldcap-tr[.]com
“Outlook Web App”
ns.altintas-goldcap-tr.com — Контент недоступний. Уособлення бренду: Microsoft; Тип шахрайства: Tech Support Scam. Зведення доказів: VirusTotal 13/94 (ADMINUSLabs, alphaMountain.ai, Cluster25, CRDF, CyRadar); URLScan malicious verdict; Spamhaus DBL_PHISH; PhishDestroy score 89/100.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
The domain ns.altintas-goldcap-tr.com was registered on March 04, 2026 and is currently listed as offline. Infrastructure analysis shows the domain resolves to the IP address 172.67.168.169, which belongs to AS13335 Cloudflare, Inc. and is geolocated in the United States. The site presented a TLS certificate rated E7, indicating a low level of certificate validation. The page title returned by the server is "Outlook Web App," suggesting an attempt to mimic a Microsoft service, which aligns with the known brand target of Microsoft and the classification of a tech‑support scam.
The domain appears on one security blocklist and has been explicitly blocked by PhishDestroy. VirusTotal scans reported 13 detections out of 94 security vendors, reinforcing the malicious assessment. Additionally, Gridinsoft assigned a trust score of 0 out of 100, confirming the lack of reputation. The elevated risk level reflects the combination of brand impersonation, low‑trust SSL, and multiple vendor detections.
While the site is currently offline, defenders should continue to monitor the associated IP address and Cloudflare ASN for any re‑use in future campaigns. Organizations should block the domain at network perimeter devices, update URL filtering rules, and educate users about unsolicited tech‑support outreach that references Microsoft services. Further investigation is needed to determine whether the infrastructure hosts additional malicious payloads or if the domain was part of a broader campaign, but the existing evidence is sufficient to justify immediate defensive actions.
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Аналіз VirusTotal
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога