tsioslzu[.]shop
“Messenger”
tsioslzu.shop — Помилка сервера (HTTP 502). Зведення доказів: VirusTotal 5/91 (alphaMountain.ai, G-Data, LevelBlue, SOCRadar, Sophos); URLQuery 2 det.; CF Radar malicious; PhishDestroy score 69/100. Реєстратор: Nicenic.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
This assessment covers tsioslzu.shop, currently under investigation for generic phishing risk. The domain’s active status and use of a messaging-themed page titled 'Messenger' raise concerns about potential credential harvesting tactics or user impersonation attempts. The risk level is classified as under investigation while technical analysis continues, as there are no definitive blocklist results to date.
Key technical indicators include a VirusTotal analysis showing 0 out of 95 detection engines flagging the domain, suggesting it has not yet been widely recognized by automated threat intelligence feeds. The domain is currently active and resolves to IP address 27.124.47.186. The SSL certificate issuer is listed as 'Telegram,' which is atypical for a shop domain and may indicate attempts to build false trust or mimic legitimate messaging platforms. No detections have been reported on common blocklists, and the initial trust score remains unestablished due to the recent visibility of the site. No specific creation date or registrar details are available in this data set.
For mitigation, users and network administrators should closely monitor for any traffic or credential submission attempts involving tsioslzu.shop, particularly if endpoints display a 'Messenger' interface. Immediate blocking of the resolved IP address (27.124.47.186) is advised pending further investigation. Security teams should educate users to avoid entering sensitive data on unverified domains, especially those mimicking trusted brands. Continued threat intelligence collection and monitoring for new detections or user reports are recommended to ensure rapid response to potential phishing activity.
Розвіддані з мережевої безпеки Registrar context
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Збережений знімок
Аналітика доменів
Технічні деталіDNS, SAN-адреси SSL, мітки часу
ICANN OVERSIGHT
Акредитація та контекст RAA
Акредитація та контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Latest Classified Outcome 2026-08-12 12:53:30 UTC
Аналіз VirusTotal
Докази та зовнішні звіти
PD-20260702-30332D Recipient: abuse@rackip.com Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога