asteroshib[.]com
“AsteroShib Marketplace”
The domain asteroshib.com was registered on May 15 2026 through NICENIC INTERNATIONAL GROUP CO. LIMITED and remains active with a high risk classification tied to generic phishing. Infrastructure analysis reveals it resolves to IP address 185.158.133.1 located in Germany and employs the nameservers jeremy.ns.cloudflare.com along with nia.ns.cloudflare.com. The site returns HTTP status 200 and presents the page title AsteroShib Marketplace while using an SSL certificate issued under Google Trust Services WE1. Domain creation occurred several weeks prior to the July 12 2026 report date yet the exact operational timeline since registration is not further detailed in the available records.
Detection metrics include appearance on four security blocklists a VirusTotal score of three detections out of ninety five vendors and a trust score of zero out of one hundred from Gridinsoft. The domain is also referenced within a single AlienVault OTX threat intelligence pulse. These indicators collectively support the generic phishing designation though the precise campaign scope or distribution vectors are not enumerated beyond the stated threat type and active status.
Uncertainties center on the full extent of any associated infrastructure or the specific entities targeted since the provided intelligence does not include campaign artifacts or additional linked domains. The continued resolution and lack of takedown as of the report date indicate ongoing accessibility that may require direct observation for confirmation of persistence.
Defenders should add both the domain asteroshib.com and the IP 185.158.133.1 to internal block lists and filters. Monitoring for additional registrations under the same nameservers or registrar patterns is advised along with review of network logs for any connections to the known IP. Regular updates to threat intelligence feeds incorporating the VirusTotal and blocklist signals can further reduce exposure to similar infrastructure.
网络安全情报 Registrar context
威胁响应 Pipeline
阻止列表覆盖
10 个来源 · 同步于 2026年8月10日
检测时间线
按时间顺序显示已存储的观测记录。
-
可用性
可用性:首次观测为 unknown
993d00c35140 -
可用性
可用性:unknown → live_content
ee64de36e76a -
可用性
可用性:live_content → unknown
37bddb99b8eb -
可用性
可用性:unknown → live_content
6eced5403a28 -
可用性
可用性:live_content → unknown
7cebcfd4071c -
可用性
可用性:unknown → live_content
c9702790137a -
可用性
可用性:live_content → unknown
ca255b61650a -
可用性
可用性:unknown → live_content
86ae852885fe -
可用性
可用性:live_content → unknown
d8f7d37d7f95 -
可用性
可用性:unknown → live_content
4c497ccecb41
域名情报
技术详情DNS、TLS 名称和时间戳
ICANN OVERSIGHT
认证和 RAA 背景
认证和 RAA 背景
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
VirusTotal 分析
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。
检查任意域名
使用存储的阻止列表、WHOIS、DNS 和公共扫描证据进行威胁分析
立即扫描举报网络钓鱼
将可疑域名提交至我们的威胁数据库——保护社区
报告实时威胁动态
最近的网络钓鱼报告和观察到的可用性变化
监控