stellaroptics[.]cn
Перевірка домену stellaroptics.cn на фішинг і безпеку
“Stellaroptics”
stellaroptics.cn — Неперевірений. Тип шахрайства: Impersonation. Зведення доказів: VirusTotal 4/93 (ChainPatrol, alphaMountain.ai, CyRadar, Seclookup); PhishDestroy score 71/100. Реєстратор: 阿里云计算有限公司(万网).
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
Analysis of the domain stellaroptics.cn indicates it was registered on February 21, 2026, through 阿里云计算有限公司 (万网), a registrar commonly used for both legitimate and malicious domains. The domain resolved to the IP address 46.202.158.210, hosted on AS47583 (Hostinger International Limited) in Germany. Infrastructure analysis reveals the use of nameservers dns23.hichina.com and dns24.hichina.com, which are associated with Alibaba Cloud and frequently observed in phishing campaigns targeting retail and e-commerce sectors. The page title, 'Stellaroptics,' suggests an attempt to mimic an optics or eyewear retailer, though no specific brand impersonation has been confirmed in available data.
At the time of assessment, the domain was offline, and no SSL certificate was present, a common characteristic of hastily deployed phishing infrastructure. Four of 93 security vendors on VirusTotal flagged stellaroptics.cn as malicious, and the domain appears on at least one security blocklist, including PhishDestroy. While the exact content of the site remains unanalyzed, the combination of a recently registered domain, absence of encryption, and detection by multiple security vendors supports its classification as a phishing threat. Defenders should treat this domain as elevated risk, particularly for users in retail or e-commerce contexts.
Network-level blocking of the IP 46.202.158.210 and the domain stellaroptics.cn is recommended. Organizations using Alibaba Cloud nameservers should monitor for similar newly registered domains, as this infrastructure is frequently repurposed for phishing. Given the domain's current offline status, further analysis may be limited, but historical DNS and WHOIS records should be preserved for potential incident response.
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Аналіз VirusTotal
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога