MALICIOUS — CRITICAL
os[.]techto[.]com[.]br
The website os.techto.com.br presented a page titled "Sign In to Get Started," indicating a credential phishing scam designed to harvest user login credentials.
- VirusTotal
- 16/91
- Blocklists
- No stored match
- Доступність
- Останній відомий активний · HTTP 200
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Notification and current-status evidence
The sent-report ledger records the first outgoing report at .
The recorded recipient is abuse@bluehost.com.
The latest stored availability evidence still shows the domain reachable; 1 month has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
Jump to section
os.techto.com.br — Останній відомий активний (HTTP 200). Уособлення бренду: Spectrum; Тип шахрайства: Credential Phishing. Зведення доказів: VirusTotal 16/91 (ADMINUSLabs, alphaMountain.ai, BitDefender, Chong Lua Dao, Cluster25); URLQuery 2 alerts; URLScan malicious verdict; Google Safe Browsing flagged; PhishDestroy score 100/100.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
Evidence Analysis
The website os.techto.com.br presented a page titled "Sign In to Get Started," indicating a credential phishing scam designed to harvest user login credentials. The site posed a threat by attempting to trick users into entering sensitive authentication information under the guise of a legitimate sign-in portal.
Technical evidence from the provided data shows the site was flagged by 15 out of 95 VirusTotal vendors, with detections from ADMINUSLabs, alphaMountain.ai, BitDefender, Chong Lua Dao, and Cluster25. Google Safe Browsing flagged it for "SOCIAL_ENGINEERING". The domain was registered on 2016-03-30 with a registrar listed as REGISTRAR_NOT_FOUND. It was hosted on IP address 162.241.155.7 (United States) under AS19871 Network Solutions, LLC, using an SSL certificate from Let's Encrypt (R12) and nameservers listed as NS_NOT_FOUND. The site utilized cdnjs and jQuery technologies.
The current status of the site is DOWN/OFFLINE. The overall risk level is high, as indicated by a DOM risk score of 83 out of 100, and the site was found on 1 blocklist.
Обсяг даних12 recorded checks
Розвіддані з мережевої безпеки
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Hagezi Threat Feed | os.techto.com.br |
malicious | Sinkholed |
| DNS4EU | os.techto.com.br |
malicious | Sinkholed |
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Аналіз VirusTotal
Докази та зовнішні звітиIndependent lookups and source reports
PD-20260619-8290F7 Recipient: abuse@bluehost.com Victim safety and official reportingImmediate actions and verified reporting channels
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.