yaohuabinhai[.]org
“TP宿¹ä¸è½½å®åææ°çæ¬2025 - æ£çå è´¹ä¸è½½ä¸å¿”
yaohuabinhai.org — Неперевірений. Тип шахрайства: Credential Phishing. Зведення доказів: VirusTotal 4/91 (Chong Lua Dao, CRDF, Gridinsoft, SOCRadar); URLQuery 2 alerts; 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 70/100. Реєстратор: GoDaddy.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
Analysis of yaohuabinhai.org indicates active credential phishing infrastructure targeting Chinese-speaking users. The domain, registered on January 20, 2025, via GoDaddy.com, LLC, currently resolves to 104.21.17.166 (Cloudflare, Inc., CA) and returns an HTTP 200 status. Nameservers coleman.ns.cloudflare.com and romina.ns.cloudflare.com confirm Cloudflare proxy usage, obscuring the origin server. The page title, "TP官方下载安卓最新版本2025 - 正版再费下载中心," suggests a fraudulent software distribution site, though the exact brand or product being mimicked remains unconfirmed without further content analysis. The domain appears on three security blocklists (PhishDestroy, MetaMask, SEAL) and holds a Gridinsoft trust score of 0/100, reinforcing its malicious classification. Detected technologies include jQuery, Google Analytics, Baidu Analytics (百度统计), and Cloudflare Browser Insights, which may facilitate user tracking or payload delivery. The presence of HTTP/3 and a Google Trust Services SSL certificate (WE1) aligns with modern phishing kits but provides no inherent legitimacy. No vendor detections were recorded at the time of the last scan, though this absence does not confirm safety. Defenders should treat this domain as high-risk, particularly for credential theft or malware distribution. Recommended actions include blocking resolution at the DNS level, monitoring for connections to 104.21.17.166, and investigating associated analytics IDs (Google/Baidu) for cross-domain tracking patterns. The domain remains active as of July 12, 2026.
Розвіддані з мережевої безпеки
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Hagezi Threat Feed | yaohuabinhai.org |
malicious | Sinkholed |
| DNS4EU | yaohuabinhai.org |
malicious | Sinkholed |
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Збережений знімок
Аналітика доменів
Технічні деталіDNS, SAN-адреси SSL, мітки часу
ICANN OVERSIGHT
Акредитація та контекст RAA
Акредитація та контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Технології · 6 identified
jQuery is a JavaScript library which is a free, open-source software designed to simplify HTML DOM tree traversal and manipulation, as well as event handling, CSS animation, and Ajax.
jquery.com 100% впевненостіGoogle Analytics is a free web analytics service that tracks and reports website traffic.
google.com 100% впевненостіCloudflare Browser Insights is a tool that measures the performance of websites from the perspective of users.
www.cloudflare.com 100% впевненостіCloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com 100% впевненостіBaidu Analytics (百度统计) is a free tool for tracking and reporting traffic data of users visiting your site.
tongji.baidu.com 100% впевненостіHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100% впевненостіАналіз VirusTotal
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога