xandil[.]ru[.]com
“Mobile.de Händler-Login”
Зведення доказів
The domain xandil.ru.com was observed hosting a credential‑phishing page that mimics the mobile.de Händler‑Login interface. Registration data indicate the domain was created through the HOST4GEEKS registrar, which is associated with ASN 393960 (Host4Geeks LLC). DNS resolution points to the IPv4 address 66.85.47.26, a server located in the United States and advertised under the same ASN. No TLS certificate was presented, meaning the site operated over plain HTTP. The authoritative name servers are cheryl.ns.cloudflare.com and logan.ns.cloudflare.com, both belonging to Cloudflare’s DNS service.
VirusTotal scans returned 13 positive detections out of 95 submitted engines, confirming that multiple security vendors consider the domain malicious. The domain is listed on a single external blocklist and has been actively blocked by the PhishDestroy mitigation service. The page title returned by the web server reads “Mobile.de Händler‑Login”, directly referencing the targeted brand. Current monitoring shows the site has been taken offline, but the underlying infrastructure – registrar, hosting ASN, and Cloudflare name servers – remains reusable for future campaigns.
Defensive teams should immediately deny traffic to 66.85.47.26, add the domain and its IP to local deny lists, and monitor for new domains registered with HOST4GEEKS that resolve to the same ASN. Continuous observation of Cloudflare name‑server patterns may reveal additional payload‑hosting domains. Because the site lacked TLS, any future re‑deployment would be detectable via HTTP‑only inspection. Until the infrastructure is retired, organizations protecting mobile.de users should treat the indicator set as high‑confidence evidence of an active credential‑phishing operation.
Data Coverage
Розвіддані з мережевої безпеки
Процес реагування на загрози Pipeline
Перевірка за блок-листами
10 зовнішніх джерел під наглядом · знімок від 11.08.2026
Хронологія виявлення
-
Статус домену
Доступний → Недоступний
-
Cloudflare Radar
Сканування Cloudflare Radar збережено · Відкрити сканування
Аналіз VirusTotal
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога