verificar-identidad[.]kesug[.]com
“Domain Suspended”
verificar-identidad.kesug.com — Неперевірений. Тип шахрайства: Account Takeover. Зведення доказів: VirusTotal 7/91 (alphaMountain.ai, CRDF, Google Safe Browsing, Gridinsoft, Lionic); CF Radar malicious; PhishDestroy score 71/100. Реєстратор: NameCheap.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
Analysis of verificar-identidad.kesug.com, observed on July 24 2026, indicates active infrastructure supporting an account takeover phishing campaign. The domain resolves to IP address 77.72.1.44, which is hosted in Great Britain under ASN 12488 owned by Krystal Hosting Ltd. The hosting provider and location are consistent with a number of previously reported malicious sites that leverage inexpensive shared hosting to conceal malicious activity. Registration data shows the domain was created on August 19 2023 through NameCheap, Inc., and continues to use the default Byet.org name server set (ns1‑ns5.byet.org). The presence of a ZeroSSL ECC Domain Secure Site CA certificate confirms the site is served over HTTPS, a tactic frequently employed to increase victim trust.
HTTP requests return a 200 status code, while the page title currently displays "Domain Suspended," suggesting the original landing page may have been removed or temporarily disabled; no content beyond the title has been captured, leaving the exact phishing payload unknown. Reputation scoring from Gridinsoft rates the domain at 0/100, indicating an extremely low trust rating. VirusTotal scans report that nine of ninety‑three antivirus vendors flag the domain as malicious, reinforcing the suspicion of abuse. The domain is listed on at least one public security blocklist and is actively blocked by the PhishDestroy service, confirming that defensive feeds consider it a threat.
The observed evidence collectively satisfies the criteria for a high‑risk, active phishing site targeting account credentials. Defenders should continue to block the domain at network perimeter devices, update URL filtering lists, and monitor for related command‑and‑control traffic originating from the 77.72.1.44 address.
Розвіддані з мережевої безпеки
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Збережений знімок
Аналітика доменів
Технічні деталіDNS, SAN-адреси SSL, мітки часу
ICANN OVERSIGHT
Registration: kesug.com
Акредитація та контекст RAA
Акредитація та контекст RAA
Registrar accreditation and DNS abuse obligations
For the registrable domain kesug.com behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Аналіз VirusTotal
Архівні докази
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога