VirusTotal
10 / 91
“Service Suspended”
ozakagi.network — Останній відомий активний (HTTP 200). Тип шахрайства: Account Takeover. Зведення доказів: VirusTotal 10/91 (alphaMountain.ai, BitDefender, Chong Lua Dao, CyRadar, Forcepoint ThreatSeeker); 3 external blocklist matches (Polkadot, Enkrypt, Codeesura); PhishDestroy score 100/100. Реєстратор: NameSilo.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
10 / 91
26 community references
Повідомитизбережений звіт
Повідомити Аналіз завершено
ПовідомитиChecked; no threat flag recorded
ПовідомитиThe domain ozakagi.network is identified as a generic phishing infrastructure specifically designed to target users of cryptocurrency platforms. Analysis indicates the domain is currently offline, though it previously displayed a 'Service Suspended' page title, a common tactic to evade immediate detection while maintaining operational readiness. No direct brand impersonation has been confirmed, but the domain's characteristics align with phishing campaigns aimed at stealing credentials or financial information from users interacting with decentralized services. Infrastructure analysis reveals the domain was registered on February 21, 2026, through NameSilo, LLC, a registrar frequently associated with high-risk domains. It resolves to the IP address 216.24.57.7, hosted on AS397273 Render in the United States. The domain is flagged by 12 of 95 security vendors on VirusTotal, indicating a significant consensus among threat intelligence providers regarding its malicious nature. Additionally, ozakagi.network appears on four security blocklists and is actively blocked by multiple cryptocurrency-focused security tools, including PhishDestroy, Polkadot, Enkrypt, and Codeesura. The SSL certificate is classified as WE1, a low-trust indicator often observed in phishing or fraudulent domains. Current status confirms the domain has been taken offline, likely due to enforcement actions or the conclusion of its operational lifecycle. However, the infrastructure remains a documented threat, and users should treat any prior interactions with the domain as compromised. Organizations and individuals are advised to block the domain and its associated IP address at the network level. Cryptocurrency users should verify the legitimacy of any service requesting credentials or transactions, particularly those linked to decentralized platforms. Monitoring for similar domains registered through NameSilo or hosted on Render’s infrastructure may help preempt future threats.
Збережені дані спостережень за взаємодією веб-сканера та браузера для цього хоста, а також перевірка відбитків у режимі реального часу для систем розподілу трафіку типу «Кейтаро».
openrestyПримітка щодо сканера: alive_content: raw=ok; http=200; via=https_direct; server=openresty
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Репутація Edge-IP не пов’язана з цим доменом.
ns2.vercel-dns.comLocation describes the IP network.
b334091452d53a1b084e2774f1a0a4866bab10678174e6b651b5335a4201c704Saved certificate metadata. Certificate dates without a timezone are shown as stored. Transport encryption does not establish that the site is trustworthy.
11 recorded events. These records describe collected evidence, outgoing notifications and publication; they do not confirm a complete investigation or a takedown.
We scan suspicious URLs, inspect public results and send evidence through the appropriate abuse-reporting channels. The dated events above show what is recorded for this domain. The directory below explains the wider workflow.
Capture the rendered page, requests and visible infrastructure.
Compare the available engine results and retain the analysis timestamp.
Check whether Google currently lists the URL as unsafe.
Inspect a public scan and its recorded network and classification data.
Look for indicator references and related community intelligence.
Compare archived captures and preserve historical context.
Look for matching indicators and associated threat records.
Inspect certificate records and related hostnames.
Compare security resolver responses and record observed blocking.
Inspect the public DNS, TLS, HTTP and technology surface.
Security services used for scanning, reputation checks and reporting are listed below. A service being listed is not evidence that it received, accepted or acted on this particular domain. Recorded submissions appear in the notification history above.
Повідомив 1 учасник спільноти; уперше помічено 03.10.2025
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Template-based draft · optional AI wording assistance requires separate consent
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразДодавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиОстанні звіти про фішинг і помічені зміни доступності
ВідстежуватиСлідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога