ai-scans[.]net
“aiScans — Multi-Chain Portfolio Tracker”
ai-scans.net — 未验证. 品牌冒充:Across; 诈骗类型:Generic Phishing. 证据摘要: VirusTotal 4/94 (alphaMountain.ai, Fortinet, Gridinsoft, SOCRadar); Spamhaus DBL_PHISH; 1 external blocklist match (ScamSniffer); PhishDestroy score 65/100. 注册商: NiceNIC.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
PhishDestroy identifies ai-scans.net as an active phishing domain under investigation, currently classified as a generic phishing threat. The site leverages AI-themed branding to deceive users into disclosing sensitive information under the guise of 'secure AI scans'. VirusTotal currently flags 4/95 engines as malicious, indicating a low detection rate despite red flags. The domain resolves to IP 188.114.97.3, registered through NICENIC INTERNATIONAL GROUP CO., LIMITED on March 24, 2026. Key indicators include a Let's Encrypt SSL certificate, which may falsely imply legitimacy, and the exceptionally recent creation date—suggesting a hastily deployed operation likely targeting unsuspecting users or exploiting emerging AI trends. Blocklist status remains unverified, but the combination of recent registration, low detection rates, and thematic deception warrants immediate scrutiny.
Technical analysis reveals a sophisticated evasion strategy: the domain avoids immediate blacklisting through short operational tenure and the use of a reputable SSL issuer. The registrar, NICENIC INTERNATIONAL, is known for accommodating high-volume registrations, some associated with malicious activity, though not inherently malicious itself. The IP address 188.114.97.3 hosts multiple domains, some previously flagged for low-reputation behavior, increasing the risk of collateral exposure. The absence of detections on VirusTotal (4/95) is misleading—many phishing kits now employ polymorphic obfuscation and delayed payload activation to bypass static scanning engines. The AI-themed branding (e.g., 'ai-scans') is a deliberate tactic to exploit current user trust in artificial intelligence tools, increasing click-through rates and lowering user skepticism.
Mitigation requires immediate, targeted actions: users must avoid interacting with the domain and report it via browser warnings or PhishDestroy’s submission portal. Organizations should block the domain at the DNS level and flag the IP range (188.114.97.0/24) in firewall rules. Security teams should investigate inbound links to ai-scans.net in email or web traffic logs. Given the low detection rate, heuristic monitoring tools should be updated to flag domains with AI-themed keywords, recent creation dates, and Let's Encrypt certificates as suspicious. Finally, users should verify any 'AI scan' service through official vendor websites, not third-party domains, to prevent credential harvesting or malware delivery under the pretext of AI validation.
网络安全情报 Registrar context
威胁响应 Pipeline
公共封禁名单状态
已保存的截图
域名情报
技术细节DNS、SSL SAN、时间戳
ICANN OVERSIGHT
认证和 RAA 背景
认证和 RAA 背景
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Latest Classified Outcome 2026-08-14 02:55:59 UTC
取证情报
所用技术 · 3 identified
Performance monitoring tool that measures website speed from real users.
www.cloudflare.comWeb infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
VirusTotal 分析
网站性能分析
Google PageSpeed Insights — mobile performance audit of ai-scans.net · checked Apr 1, 2026
证据与外部报告
PD-20260401-C477D8 Recipient: abuse@nicenic.net, abuse@verisign-grs.com, compliance@icann.org 您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。