sophonic[.]xyz
“רק רגע...”
sophonic.xyz — Контент недоступний (HTTP 502). Зведення доказів: VirusTotal 5/95 (alphaMountain.ai, Forcepoint ThreatSeeker, Fortinet, Gridinsoft, Sophos); PhishDestroy score 65/100. Реєстратор: PDR.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
This domain, sophonic.xyz, is flagged as a credential-harvesting phishing site designed to mimic legitimate login portals. Analysis of the page title "רק רגע..." (Hebrew for "Just a moment...") and infrastructure patterns indicates an attempt to deceive users into submitting account credentials, likely targeting regional or language-specific audiences. The elevated risk level is assigned due to the site's confirmed intent to harvest sensitive login information, which can lead to account takeovers or further malicious activity such as fraud or identity theft. Infrastructure analysis reveals the domain was registered on July 31, 2025, through PDR Ltd. d/b/a PublicDomainRegistry.com. It resolved to the IP address 172.67.204.102 and was flagged by 5 out of 95 security vendors on VirusTotal. The domain appears on one security blocklist and was assigned a trust score of 0/100 by Gridinsoft. The site was subsequently taken offline and blocked by at least one security entity, though residual risks may persist due to potential re-activation or similar infrastructure reuse. Mitigation steps for this credential-harvesting threat include immediate revocation of any credentials potentially exposed to the site. Organizations should implement domain-based blocking for sophonic.xyz and monitor for related indicators, such as the IP 172.67.204.102 or newly registered domains from the same registrar. Users are advised to enable multi-factor authentication (MFA) on all accounts and verify the legitimacy of login portals before submitting credentials. Security teams should conduct retrospective log analysis to identify any prior interactions with this domain or its associated infrastructure.
Розвіддані з мережевої безпеки
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Збережений знімок
Аналітика доменів
Технічні деталіDNS, SAN-адреси SSL, мітки часу
ICANN OVERSIGHT
Акредитація та контекст RAA
Акредитація та контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Криміналістичні дані
Аналіз VirusTotal
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога