tia[.]beefyhubs[.]life
“Google”
tia.beefyhubs.life — Контент недоступний (HTTP 502). Уособлення бренду: Google; Тип шахрайства: Brand Impersonation. Зведення доказів: VirusTotal 13/95 (ChainPatrol, alphaMountain.ai, BitDefender, CRDF, CyRadar); PhishDestroy score 89/100. Реєстратор: Cloudflare.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
This domain, tia.beefyhubs.life, is identified as a brand_impersonation threat targeting Gmail users. Analysis indicates the site presents a fraudulent Google login interface, designed to harvest credentials, authentication tokens, and potentially enable account takeover. The page title explicitly mimics the legitimate service, displaying 'Google' to deceive users into entering sensitive information. No associated drainer kit or secondary payload delivery was observed in preliminary analysis, though credential harvesting remains the primary objective. Technical indicators reveal the domain was registered through Cloudflare, Inc., a registrar frequently utilized for both legitimate and malicious infrastructure. It resolves to the IP address 142.250.186.68, geolocated in Germany under AS15169 (Google LLC), suggesting potential IP spoofing or misconfiguration to evade detection. At the time of analysis, VirusTotal detection rates stood at 13 out of 95 security vendors, while the domain appeared on a single security blocklist. No SSL certificate was present, increasing the likelihood of interception or man-in-the-middle attacks. Creation date metadata was unavailable, limiting temporal attribution, though the domain's rapid takedown suggests reactive mitigation. The domain is currently offline, likely following detection and reporting by security entities such as PhishDestroy. While the immediate threat has been neutralized, residual risk persists due to potential credential reuse by affected users. Infrastructure analysis reveals the use of Cloudflare registrars and Google-hosted IPs, a tactic observed in other phishing campaigns to blend with legitimate traffic. Users are advised to revoke any sessions initiated on this domain, enable multi-factor authentication, and monitor accounts for unauthorized activity. Organizations should update blocklists to include tia.beefyhubs.life and its resolved IP, while security teams should investigate potential lateral movement from harvested credentials.
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Збережений знімок
Аналітика доменів
Технічні деталіDNS, SAN-адреси SSL, мітки часу
ICANN OVERSIGHT
Registration: beefyhubs.life
Акредитація та контекст RAA
Акредитація та контекст RAA
Registrar accreditation and DNS abuse obligations
For the registrable domain beefyhubs.life behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Криміналістичні дані
Аналіз VirusTotal
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога