site-3fejh9hgr[.]godaddysites[.]com
“Anmeldung UPC Mail”
site-3fejh9hgr.godaddysites.com — Контент недоступний. Уособлення бренду: Godaddy. Зведення доказів: VirusTotal 13/93 (alphaMountain.ai, BitDefender, CRDF, Forcepoint ThreatSeeker, G-Data); PhishDestroy score 89/100. Реєстратор: GoDaddy.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
Analysis as of July 24 2026 indicates that the sub‑domain site-3fejh9hgr.godaddysites.com was used to host a phishing page titled “Anmeldung UPC Mail”. The domain is registered through GoDaddy.com, LLC and has been active since 18 Nov 2013. DNS resolution points to IP 13.248.243.5, which belongs to Amazon.com, Inc. (AS16509) and is located in the United States. The host is served behind GoDaddy’s default nameservers cns1.secureserver.net and cns2.secureserver.net, and the TLS certificate presented is a Go Daddy Secure Certificate Authority – G2 issued to GoDaddy.com, Inc., confirming the legitimate certificate chain but offering no protection against malicious content. The page was flagged by PhishDestroy and is listed on one security blocklist.
VirusTotal scans show that 13 of 93 antivirus or URL‑reputation engines flagged the domain, indicating a moderate detection rate. HTTP probing returned a 404 status code, and the current operational status is recorded as offline, suggesting the phishing page has been taken down. Nonetheless, the historical evidence of phishing activity remains relevant for threat‑intel correlation. Defenders should continue to monitor the IP address 13.248.243.5 for any re‑use in future campaigns, especially since the Amazon hosting environment is frequently leveraged for transient malicious infrastructure.
Existing blocklist entries should be maintained, and any outbound traffic to this host should be denied or logged. Because the domain’s registration details are publicly available and the SSL certificate is valid, reputation‑based filtering alone may not be sufficient; supplemental URL‑reputation checks and cross‑reference with the 13 VirusTotal detections are advisable. In environments where users may receive emails purporting to be from UPC, security awareness training should highlight the “Anmeldung UPC Mail” title as a known indicator of compromise. Continuous review of GoDaddy‑hosted sub‑domains for similar patterns is recommended.
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Збережений знімок
Аналітика доменів
Технічні деталіDNS, SAN-адреси SSL, мітки часу
ICANN OVERSIGHT
Registration: godaddysites.com
Акредитація та контекст RAA
Акредитація та контекст RAA
Registrar accreditation and DNS abuse obligations
For the registrable domain godaddysites.com behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Аналіз VirusTotal
Архівні докази
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога