popa-market[.]xyz
“popa-market.xyz”
popa-market.xyz — Неперевірений. Тип шахрайства: Generic Phishing. Зведення доказів: VirusTotal 8/91 (alphaMountain.ai, BitDefender, Chong Lua Dao, Forcepoint ThreatSeeker, G-Data); URLQuery 2 alerts; PhishDestroy score 74/100. Реєстратор: REGRU-RU.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
This domain, popa-market.xyz, is flagged as an active credential phishing site based on multiple technical indicators. Registered on March 11, 2026, through a Russian registrar, the domain currently resolves to 84.200.89.74, an IP address geolocated in Germany and associated with AS214036. The hosting infrastructure employs Nginx as a web server, with Cloudflare and Unpkg technologies detected, alongside HSTS enforcement and cdnjs library usage. These components suggest an attempt to mimic legitimate e-commerce or marketplace platforms while leveraging content delivery networks to obscure malicious activity. Analysis indicates the domain has been listed on at least one security blocklist, with two out of ninety-five security vendors on VirusTotal identifying it as malicious. The SSL certificate, issued by Let's Encrypt, provides encryption but does not validate the legitimacy of the site's content. The domain's nameservers, ns1.reg.ru and ns2.reg.ru, further link it to infrastructure commonly associated with phishing operations. While the page title and HTTP 200 status suggest an operational frontend, no specific brand impersonation or phishing kit has been conclusively identified in available data. Defenders should treat this domain as high-risk due to its recent registration, blocklist presence, and technical configuration. The use of Cloudflare and HSTS may complicate takedown efforts, requiring coordination with hosting providers and certificate authorities. Network-level blocking of the resolved IP and associated domain should be prioritized, alongside monitoring for related subdomains or certificate renewals. Given the domain's active status as of July 12, 2026, continued vigilance is recommended, particularly for organizations with users who may encounter marketplace-themed phishing lures.
Розвіддані з мережевої безпеки
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DNS4EU | popa-market.xyz |
malicious | Sinkholed |
| Hagezi Threat Feed | popa-market.xyz |
malicious | Sinkholed |
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Збережений знімок
Аналітика доменів
Технічні деталіDNS, SAN-адреси SSL, мітки часу
ICANN OVERSIGHT
Акредитація та контекст RAA
Акредитація та контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Технології · 5 identified
High-performance HTTP server and reverse proxy, known for stability and low resource usage.
Web infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comFast CDN for everything on npm — serves raw files from npm packages.
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
Аналіз VirusTotal
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога