uk[.]paying-ck[.]vip
“Welcome to GOV.UK”
uk.paying-ck.vip — Контент недоступний (HTTP 502). Тип шахрайства: Generic Phishing. Зведення доказів: VirusTotal 10/95 (BitDefender, CRDF, CyRadar, ESET, Fortinet); Spamhaus DBL_PHISH; PhishDestroy score 80/100. Реєстратор: Alibaba Cloud Computing.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
This domain, uk.paying-ck.vip, poses a high-risk phishing threat by impersonating the official GOV.UK platform. Visitors are presented with a fraudulent payment portal designed to harvest sensitive financial or personal information under the guise of a legitimate government service. The page title, 'Welcome to GOV.UK,' is a clear attempt to deceive users into believing they are interacting with an authentic UK government website, increasing the likelihood of successful credential theft or financial fraud.
Analysis indicates this domain was registered on December 17, 2025, through Alibaba Cloud Computing Ltd. d/b/a HiChina, a registrar frequently associated with malicious infrastructure. Infrastructure analysis reveals the domain resolves to 151.101.0.144, hosted on AS54113 (Fastly, Inc.), a network often exploited for content delivery of phishing campaigns. Security vendors have flagged this domain as malicious, with 10 out of 95 engines on VirusTotal detecting it as a phishing threat. Additionally, it appears on one security blocklist, further confirming its fraudulent nature. The absence of an SSL certificate is another red flag, as legitimate government sites universally employ encryption to protect user data.
If you have visited uk.paying-ck.vip or entered any information on this site, immediate action is required. First, cease all interaction with the domain and avoid clicking any links or downloading files from it. Next, change passwords for any accounts that may have been exposed, particularly those tied to financial services or government portals. Monitor bank statements and credit reports for unauthorized transactions, and consider placing a fraud alert with credit bureaus. Report the incident to relevant authorities, such as the UK National Cyber Security Centre (NCSC) or local cybercrime units, to aid in tracking and mitigating the threat. Users should also verify the legitimacy of any unexpected government communications by accessing official websites directly through verified URLs.
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Збережений знімок
Аналітика доменів
Технічні деталіDNS, SAN-адреси SSL, мітки часу
ICANN OVERSIGHT
Registration: paying-ck.vip
Акредитація та контекст RAA
Акредитація та контекст RAA
Registrar accreditation and DNS abuse obligations
For the registrable domain paying-ck.vip behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Аналіз VirusTotal
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога