scuba-steve[.]com
“AlgorynMunt Group”
Зведення доказів
Analysis shows that www.scuba-steve.com was registered on February 21, 2026 and is presently taken offline. The domain resolves to IP address 143.204.194.29, which belongs to Amazon's AS16509 infrastructure and is geolocated in France. The TLS certificate presented is an Amazon RSA 2048 M01 certificate issued via AWS Certificate Manager, confirming the use of Amazon Web Services for hosting. Underlying server software includes Ubuntu, Nginx, and a Vue.js front‑end, with static assets served through Unpkg and distribution via Amazon CloudFront.
Nameserver delegation points to a2.share-dns.com and b2.share-dns.net, indicating the use of a shared DNS service. The page title returned from the site is "AlgorynMunt Group," suggesting the site attempts to masquerade as that entity, although no further brand evidence is present. Security telemetry indicates the domain appears on a single security blocklist and has been blocked by PhishDestroy. Gridinsoft assigns a trust score of 0 out of 100, reflecting a high risk perception.
VirusTotal scanning recorded a single positive detection out of 93 vendor engines, reinforcing the suspicion of malicious intent. Defenders should immediately block the domain and its associated IP at perimeter defenses, update URL filtering policies, and add the domain to internal blocklists. Continuous monitoring of the IP range and ASN for new domains using similar technology stacks is advised, as the infrastructure pattern—AWS hosting with shared DNS and low‑trust scores—has been observed in other phishing campaigns. Incident response teams should also review any outbound traffic logs for connections to 143.204.194.29 and correlate with user reports to identify potential exposure before the site was taken offline.
Data Coverage
Процес реагування на загрози Pipeline
Перевірка за блок-листами
10 зовнішніх джерел під наглядом · знімок від 11.08.2026
Збережений знімок
Аналітика доменів
Технічні подробиціDNS, імена TLS і часові мітки
ICANN OVERSIGHT
Акредитація та контекст RAA
Акредитація та контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Аналіз VirusTotal
Аналіз продуктивності сайту
Google PageSpeed Insights — mobile performance audit of scuba-steve.com · checked Mar 2, 2026
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога