sx[.]xmugrg[.]net
“Login”
sx.xmugrg.net — Контент недоступний (HTTP 502). Уособлення бренду: Microsoft; Тип шахрайства: Generic Phishing. Зведення доказів: VirusTotal 18/91 (BitDefender, Cluster25, CRDF, CyRadar, ESET); URLQuery 1 alert; URLScan malicious verdict; Google Safe Browsing flagged; CF Radar malicious; PhishDestroy score 98/100. Реєстратор: IONOS SE.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
This domain, sx.xmugrg.net, is flagged as a high-risk phishing infrastructure designed to deceive users through a counterfeit directory listing interface. Analysis indicates the threat type involves brand impersonation, where attackers exploit an open directory structure to distribute malicious payloads or harvest credentials. The page title 'Index of /' suggests an intentionally exposed server directory, a tactic commonly used to lend false legitimacy to phishing pages or to host secondary exploit files. Infrastructure analysis reveals the domain was registered through IONOS SE on May 23, 2026, an anomalous creation date that may indicate domain spoofing or a compromised registration process. It resolves to the IP address 82.165.104.102, located in Germany under AS8560 (IONOS SE). The domain is currently active and appears on at least one security blocklist, while Google Safe Browsing explicitly flags it as phishing. The SSL certificate, issued by Let's Encrypt (YR2), provides encryption but does not validate the site's legitimacy. VirusTotal reports 18 out of 95 security vendors detecting the domain as malicious, a detection rate consistent with active phishing campaigns. Mitigation requires immediate blocking of the domain and its resolving IP at the network perimeter. Organizations should prioritize user education on recognizing fake directory listings and open server pages, particularly those mimicking legitimate file repositories. Security teams are advised to monitor for connections to 82.165.104.102 and review logs for interactions with sx.xmugrg.net. Given the domain's registration through a major provider, additional scrutiny of similarly structured domains under IONOS SE is recommended to identify potential lateral threats. Endpoint protection should be configured to flag or quarantine any files downloaded from this infrastructure.
Розвіддані з мережевої безпеки
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DNS4EU | sx.xmugrg.net |
malicious | Sinkholed |
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Збережений знімок
Аналітика доменів
Технічні деталіDNS, SAN-адреси SSL, мітки часу
ICANN OVERSIGHT
Registration: xmugrg.net
Акредитація та контекст RAA
Акредитація та контекст RAA
Registrar accreditation and DNS abuse obligations
For the registrable domain xmugrg.net behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Технології · 8 identified
Bootstrap is a free and open-source CSS framework directed at responsive, mobile-first front-end web development. It contains CSS and JavaScript-based design templates for typography, forms, buttons, navigation, and other interface components.
getbootstrap.com 100% впевненостіApache is a free and open-source cross-platform web server software.
httpd.apache.org 100% впевненостіCloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com 100% впевненостіjQuery CDN is a way to include jQuery in your website without actually downloading and keeping it your website's folder.
code.jquery.com 100% впевненостіjQuery is a JavaScript library which is a free, open-source software designed to simplify HTML DOM tree traversal and manipulation, as well as event handling, CSS animation, and Ajax.
jquery.com 100% впевненостіGoogle Hosted Libraries is a stable, reliable, high-speed, globally available content distribution network for the most popular, open-source JavaScript libraries.
developers.google.com 100% впевненостіPopper is a positioning engine, its purpose is to calculate the position of an element to make it possible to position it near a given reference element.
popper.js.org 100% впевненостіАналіз VirusTotal
Докази та зовнішні звіти
PD-20260618-16B8E0 Recipient: abuse@ionos.com Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога