resmi-girisi[.]icu
resmi-girisi.icu — Доступно · доступ обмежено (HTTP 403). Тип шахрайства: Credential Phishing. Зведення доказів: VirusTotal 5/91 (alphaMountain.ai, CRDF, Forcepoint ThreatSeeker, Gridinsoft, SOCRadar); PhishDestroy score 76/100. Реєстратор: NiceNIC.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
The domain resmi-girisi.icu was registered on May 01, 2026 through NICENIC INTERNATIONAL GROUP CO., LIMITED and is currently active. It is protected by a Let’s Encrypt certificate (profile E8) and resolves to the Cloudflare‑managed address 104.21.60.113. The site returns an HTTP 403 status code, indicating that direct content retrieval is blocked or restricted.
Infrastructure analysis shows the host IP is assigned to a Cloudflare network located in Canada, and the domain uses the default Cloudflare authoritative nameservers craig.ns.cloudflare.com and gracie.ns.cloudflare.com. The use of Cloudflare’s edge services is consistent with a strategy to hide the true origin server and to benefit from DDoS mitigation and SSL termination.
Detection feeds have flagged the domain as malicious. Four out of ninety‑five antivirus engines on VirusTotal have marked the host as suspicious, and Gridinsoft assigns a trust score of 0 out of 100. The domain appears on a single public blocklist and is referenced in one AlienVault OTX pulse. PhishDestroy has already added the domain to its blocklist, confirming active mitigation by external defenders.
Because the site returns only a 403 response, the exact phishing payload or credential‑harvesting page cannot be examined, leaving the specific lure and target brand unknown. Defenders should continue to block the domain at network perimeter, update DNS filtering policies, and consider sinkholing the IP address to prevent future abuse. Continuous monitoring of the IP and associated Cloudflare accounts is advised, as the infrastructure could be repurposed for additional campaigns.
Розвіддані з мережевої безпеки Registrar context
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Аналітика доменів
Технічні деталіDNS, SAN-адреси SSL, мітки часу
ЗОНА SHORTDOT · ПУБЛІЧНІ ДОКАЗИ
.icu
ShortDot zone evidence
ShortDot zone evidence
The linked repository preserves daily zone observations across seven ShortDot-operated TLDs, including registration volume and abuse-related indicators. This registry context is supporting background and is not an independent detection for the domain in this report.
ICANN OVERSIGHT
Акредитація та контекст RAA
Акредитація та контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Latest Classified Outcome 2026-08-17 02:30:20 UTC
Аналіз VirusTotal
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога