aster-trade[.]app
“aster-trade.app | 521: Web server is down”
aster-trade.app — 内容不可用 (HTTP 502). 证据摘要: VirusTotal 13/91 (ADMINUSLabs, alphaMountain.ai, BitDefender, CRDF, CyRadar); URLQuery 2 alerts; PhishDestroy score 93/100.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
Analysis indicates that aster-trade.app is linked to a confirmed phishing operation. The domain was registered on February 21, 2026 and resolves to the IP address 172.67.188.58, which is owned by Cloudflare (AS13335) and geolocated to the United States. The site currently returns an HTTP 521 status code, meaning the origin web server is down, and the SSL certificate presented is identified as WE1. DNS resolution is handled by the Cloudflare nameservers igor.ns.cloudflare.com and rafe.ns.cloudflare.com, confirming the use of Cloudflare’s DNS infrastructure.
Detection data show that nine of ninety‑five VirusTotal scanners have flagged the domain as malicious, and AlienVault OTX includes it in a single threat‑intelligence pulse. The domain is blocked by PhishDestroy and appears on an additional public blocklist, bringing its blocklist coverage to multiple sources. The only page title captured is "aster-trade.app | 521: Web server is down," which provides no explicit indication of the targeted brand or lure. No further artefacts such as phishing kits, payload samples, or content screenshots have been published, and the site remains offline, leaving the exact malicious payload unknown.
Defenders should immediately block DNS resolution to aster-trade.app and any sub‑domains, add the IP address 172.67.188.58 to network deny lists, and monitor outbound traffic to Cloudflare edge nodes that could be reused for future re‑hosting. Continuous monitoring of VirusTotal, OTX, and PhishDestroy updates is recommended, as well as reviewing email filtering rules for references to "aster‑trade" to intercept potential phishing attempts. Given the observed detection footprint and presence on multiple blocklists, the domain should be treated as high‑confidence phishing infrastructure.
网络安全情报
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DigiCert UltraDNS | bscrpc.com |
malicious | Sinkholed |
| DNS0 Zero | aster-trade.app |
malicious | Sinkholed |
威胁响应 Pipeline
公共封禁名单状态
VirusTotal 分析
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。