c51691985319[.]ngrok-free[.]app
“ERR_NGROK_6024 - You are about to visit c51691985319.ngrok-free.app, served by 185.150.25.240. This…”
c51691985319.ngrok-free.app — 内容不可用. 证据摘要: VirusTotal 6/95 (alphaMountain.ai, CyRadar, Dr.Web, ESET, Fortinet); PhishDestroy score 68/100. 注册商: AMAZO-ZFRA (ASN: 16509).
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
Analysis of c51691985319.ngrok-free.app indicates this domain was a transient phishing endpoint hosted via ngrok's free tunneling service. As of July 25, 2026, the domain resolves to 3.125.102.39 (AS16509, Amazon.com, Inc., DE) and presents a 404 HTTP status, suggesting the malicious content has been removed or the tunnel terminated. The page title, 'ERR_NGROK_6024 - You are about to visit c51691985319.ngrok-free.app, served by 185.150.25.240,' is consistent with ngrok's default interstitial warning, which appears when users attempt to access a free subdomain. This warning does not confirm malicious intent but signals the domain was publicly exposed via ngrok's infrastructure, a common tactic for phishing campaigns due to its ephemeral nature and lack of persistent registration requirements. Six of 95 security vendors on VirusTotal flagged the domain, though the specific detection logic is not publicly available.
The domain appears on at least one security blocklist, and PhishDestroy has explicitly blocked it. The SSL certificate, issued by Let's Encrypt (serial E7), provides no additional attribution, as free certificates are standard for ngrok-hosted endpoints. No brand, kit, or specific scam type is identified in the available data; the domain is classified as generic phishing based on blocklist inclusion and vendor detections. The hosting IP (3.125.102.39) is part of Amazon's cloud infrastructure, which is frequently leveraged for short-lived malicious endpoints due to its scalability and low cost. Defenders should treat this domain as compromised infrastructure.
While the endpoint is currently offline, ngrok-free.app subdomains are often recycled or reused for new campaigns. Network-level blocking of the domain and associated IP (3.125.102.39) is recommended, alongside monitoring for new subdomains under ngrok-free.app with similar patterns (e.g., randomized alphanumeric strings).
威胁响应 Pipeline
公共封禁名单状态
VirusTotal 分析
存档证据
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。