app[.]arbtirum[.]sbs
“404 Not Found”
app.arbtirum.sbs — 服务器错误 (HTTP 502). 诈骗类型:Credential Phishing. 证据摘要: VirusTotal 13/91 (ChainPatrol, alphaMountain.ai, BitDefender, Chong Lua Dao, CRDF); Spamhaus DBL_PHISH; PhishDestroy score 89/100. 注册商: NiceNIC.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
PhishDestroy identifies app.arbtirum.sbs as a live credential-harvesting domain designed to mimic a legitimate application portal in order to trick users into surrendering usernames and passwords. This site poses an immediate risk to anyone who receives a link or sees the domain in messages, search results, or pop-ups promising quick app access. Because it remains active and is not yet flagged by most security engines—currently showing 0 detections out of 95 engines on VirusTotal—it can evade filters long enough to harvest a meaningful number of victims before takedown efforts catch up. The domain’s low reputation combined with its recent appearance makes it especially dangerous for users who are not actively monitoring their browsing environment. This domain was flagged by PhishDestroy after deep DNS and behavioral analysis revealed a recently registered site with no legitimate ties to any known application ecosystem. It resolves to 104.21.61.40, a hosting address shared with numerous low-trust endpoints, and uses a Let’s Encrypt certificate to appear legitimate. Despite its clean SSL profile, the site exhibits classic phishing hallmarks: mismatched branding, inconsistent page layouts, and input fields that transmit data to external servers rather than the claimed application backend. At present, VirusTotal shows zero detections across its entire engine list, underscoring how new and unclassified this threat remains. If you visited app.arbtirum.sbs, immediately change any passwords you may have entered and enable multi-factor authentication on all accounts accessed from that device. Run a full antivirus scan to check for follow-on malware, inspect browser extensions for unauthorized access, and clear cached credentials. Report the domain to your security team or phishing abuse channels so it can be blocked at the network level. Avoid reopening the site, even to “check if it’s real,” as interaction can signal active interest to attackers and prolong the threat window.
网络安全情报 Registrar context
威胁响应 Pipeline
公共封禁名单状态
已保存的截图
域名情报
技术细节DNS、SSL SAN、时间戳
SHORTDOT 域名区 · 公开证据
.sbs
ShortDot zone evidence
ShortDot zone evidence
The linked repository preserves daily zone observations across seven ShortDot-operated TLDs, including registration volume and abuse-related indicators. This registry context is supporting background and is not an independent detection for the domain in this report.
ICANN OVERSIGHT
Registration: arbtirum.sbs
认证和 RAA 背景
认证和 RAA 背景
Registrar accreditation and DNS abuse obligations
For the registrable domain arbtirum.sbs behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Latest Classified Outcome 2026-08-16 02:37:54 UTC
所用技术 · 3 identified
Performance monitoring tool that measures website speed from real users.
www.cloudflare.comWeb infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
VirusTotal 分析
网站性能分析
Google PageSpeed Insights — mobile performance audit of app.arbtirum.sbs · checked Apr 14, 2026
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。