sale-id6284729[.]info
sale-id6284729.info — Помилка сервера (HTTP 502). Уособлення бренду: Google; Тип шахрайства: Brand Impersonation. Зведення доказів: VirusTotal 4/93 (Fortinet, G-Data, SOCRadar, Sophos); URLQuery 2 alerts; Spamhaus DBL_PHISH; PhishDestroy score 68/100. Реєстратор: NiceNIC.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
The domain sale-id6284729.info was registered on February 27, 2026 through NiceNIC International Group Co., Limited and is currently taken offline. Infrastructure analysis shows the domain resolves to IP address 188.114.97.3, which belongs to AS13335 Cloudflare, Inc., placing the host in the United States. Both authoritative nameservers, deb.ns.cloudflare.com and johnny.ns.cloudflare.com, are Cloudflare‑provided, indicating the attacker leveraged Cloudflare’s CDN and DNS services to hide origin infrastructure. No TLS certificate is presented for the domain, meaning HTTPS connections would be unavailable or would fall back to plain HTTP, a common practice for temporary malicious sites.
The HTTP response that was captured before takedown displayed a page title of "Just a moment...", a generic placeholder that offers no insight into the content or any credential‑harvesting forms. The site was flagged by the PhishDestroy blocklist and appears on a single additional security blocklist, confirming that at least one external sinkhole has identified it as malicious. Reputation scoring from Gridinsoft assigned a trust score of 0 out of 100, effectively rating the domain as completely untrusted. VirusTotal scans reported that four of ninety‑three antivirus engines flagged the domain, providing modest but corroborating detection evidence.
The domain is explicitly marked as a brand‑impersonation campaign targeting Google, though the exact phishing technique or payload was not observed before the takedown. Because the site is offline, a full content‑level examination is not possible, leaving the precise user‑facing artifacts uncertain. Defenders should continue to block the domain at network perimeter, add the IP 188.114.97.3 to any threat‑intel watchlists, and monitor for future registrations that reuse the same registrar, nameservers, or Cloudflare ASN.
Розвіддані з мережевої безпеки Registrar context
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Збережений знімок
Аналітика доменів
Технічні деталіDNS, SAN-адреси SSL, мітки часу
ICANN OVERSIGHT
Акредитація та контекст RAA
Акредитація та контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Latest Classified Outcome 2026-08-21 03:24:42 UTC
Криміналістичні дані
Аналіз VirusTotal
Докази та зовнішні звіти
PD-20260227-3E451C Recipient: abuse@nicenic.net, abuse@identitydigital.com, compliance@icann.org Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога