ponz[.]family
“Explore pons”
ponz.family — Неперевірений. Уособлення бренду: Across; Тип шахрайства: Crypto Drainer. Зведення доказів: VirusTotal 4/91 (alphaMountain.ai, Forcepoint ThreatSeeker, Gridinsoft, SOCRadar); 1 external blocklist match (ScamSniffer); PhishDestroy score 65/100. Реєстратор: NameSilo.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
On 2026-08-07 SOC analysts reviewed the newly observed domain ponz.family. The WHOIS record shows the domain was registered through NameSilo, LLC and its creation timestamp is 2026-07-16, indicating a recent launch. DNS resolution points to the IPv4 address 45.9.148.108; no additional A or CNAME records were observed. The domain is currently listed on two public blocklists, specifically PhishDestroy and ScamSniffer, and both services have flagged it as malicious. VirusTotal reports that the domain has been scanned by 91 antivirus and URL-reputation engines; none of the engines raised a detection at the time of analysis.
The absence of detections does not constitute a safety guarantee, as many scanners rely on signatures that may not yet cover this campaign. No TLS certificate data, HTTP response codes, or page-title information have been published, and automated crawlers have not returned a content fingerprint. Consequently, the specific brand or service being impersonated remains unknown, and the exact phishing vector cannot be confirmed. The limited evidence suggests the infrastructure is being used for a generic phishing operation, but the lack of payload samples leaves the precise tactics, techniques, and procedures (TTPs) unverified.
Defenders should treat ponz.family as a high-confidence indicator of compromise. Immediate mitigation steps include adding the domain and its resolving IP 45.9.148.108 to network deny lists, updating DNS filtering policies to block resolution, and ensuring that email gateways enforce URL-reputation checks that incorporate the PhishDestroy and ScamSniffer feeds. Continuous monitoring for any new hostnames, changes in SSL configuration, or appearance of the domain in sandboxed traffic is advised. If future analysis yields page content or credential-stealing forms, the findings should be correlated with existing phishing kits to refine detection rules.
Розвіддані з мережевої безпеки Registrar context
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Збережений знімок
Аналітика доменів
Технічні деталіDNS, SAN-адреси SSL, мітки часу
ICANN OVERSIGHT
Акредитація та контекст RAA
Акредитація та контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Перехресна перевірка даних про загрози · source references
Технології · 1 identified
Nginx is a web server that can also be used as a reverse proxy, load balancer, mail proxy and HTTP cache.
nginx.org 100% впевненостіАналіз VirusTotal
Архівні докази
Аналіз продуктивності сайту
Google PageSpeed Insights — mobile performance audit of ponz.family · checked Aug 7, 2026
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога