Notification and current-status evidence
The sent-report ledger records the first outgoing report at .
The recorded recipient is abuse@enom.com.
The latest stored availability evidence still shows the domain reachable; 1 month has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
staholding[.]com
Перевірка домену staholding.com на фішинг і безпеку
“SharePoint - Shared with you”
staholding.com — Останній відомий активний (HTTP 200). Тип шахрайства: Generic Phishing. Зведення доказів: VirusTotal 12/91 (alphaMountain.ai, BitDefender, Cluster25, CRDF, Forcepoint ThreatSeeker); URLQuery 2 alerts; PhishDestroy score 100/100. Реєстратор: ENOM.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
staholding.com is currently active and resolves to 94.46.166.92, an address owned by AS24768 ALMOUROLTEC SERVICOS DE INFORMATICA E INTERNET LDA in Portugal. The domain, registered on August 3, 2007 through ENOM, INC., uses the nameservers ns1.infmaster.com.br and ns2.infmaster.com.br and presents a valid Let's Encrypt certificate (R12). HTTP requests return status 200 and the only visible page title is “SharePoint – Shared with you”, indicating an attempt to masquerade as a Microsoft SharePoint sharing notification. The site hosts a range of third‑party components including Typekit, Google Tag Manager, Google Analytics, cdnjs, Cookiebot, Cloudflare, and AppNexus, and enforces HSTS. Email infrastructure is minimal, with an MX record pointing to the domain itself. Threat intelligence shows that seven of ninety‑one VirusTotal scanners have flagged the host, the domain appears on one security blocklist and is listed by PhishDestroy. Gridinsoft assigns a trust score of 0/100, reinforcing the malicious assessment. The combination of a legitimate‑looking SharePoint title, high‑risk classification, and observed detections suggests the domain is being used for generic phishing campaigns, likely to harvest credentials or deliver malicious payloads. Defenders should block both the domain and its resolved IP at network perimeters, monitor DNS queries for the associated nameservers, and consider sinkholing the address. Ongoing observation is advised because the site content beyond the title has not been publicly dissected.
Розвіддані з мережевої безпеки
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| OpenDNS | staholding.com |
phishing | Phishing Block |
| Hagezi Threat Feed | staholding.com |
malicious | Sinkholed |
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Збережений знімок
Аналітика доменів
Технічні деталіDNS, SAN-адреси SSL, мітки часу
ICANN OVERSIGHT
Акредитація та контекст RAA
Акредитація та контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Технології · 8 identified
Typekit is an online service which offers a subscription library of fonts.
typekit.com 100% впевненостіHTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org 100% впевненостіGoogle Tag Manager is a tag management system (TMS) that allows you to quickly and easily update measurement codes and related code fragments collectively known as tags on your website or mobile app.
www.google.com 100% впевненостіGoogle Analytics is a free web analytics service that tracks and reports website traffic.
google.com 100% впевненостіCookiebot is a cloud-driven solution that automatically controls cookies and trackers, enabling full GDPR/ePrivacy and CCPA compliance for websites.
www.cookiebot.com 100% впевненостіCloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com 100% впевненостіAppNexus is a cloud-based software platform that enables and optimizes programmatic online advertising.
appnexus.com 100% впевненостіАналіз VirusTotal
Докази та зовнішні звіти
PD-20260617-CF2CE6 Recipient: abuse@enom.com Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога