darfilarmikrozauym[.]ru
“ÐаймÑ. ÐÑедиÑнÑе займє
darfilarmikrozauym.ru — 内容不可用. 证据摘要: VirusTotal 2/91 (Gridinsoft, SOCRadar); PhishDestroy score 76/100. 注册商: REGRU-RU.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
Analysis of the domain darfilarmikrozauym.ru shows a newly registered Russian‑language site created on July 11, 2026 and still active as of July 14, 2026. The domain is registered through REGRU‑RU and uses the hosting provider’s default nameservers ns1.hosting.reg.ru and ns2.hosting.reg.ru. DNS resolution points to the IPv4 address 31.31.198.113, which returns an HTTP 200 response. The only visible content is the page title "Займы. Кредитные займы" ("Loans. Credit loans"), indicating that the site is presenting itself as a loan or credit service. No additional infrastructure details, such as ASN, hosting location, or associated malware kits, are available. The combination of a recent registration, generic loan terminology, and a functional web server suggests the domain could be used for credential harvesting or financial‑information phishing, consistent with the generic_phishing classification. Defenders should consider adding the domain to block lists, monitor DNS queries for the associated IP, and alert users about unsolicited loan offers originating from unknown Russian‑registered sites. Further investigation, including content retrieval and traffic analysis, is recommended to confirm the presence of malicious payloads or credential‑capture mechanisms.
威胁响应 Pipeline
公共封禁名单状态
所用技术 · 2 identified
Nginx is a web server that can also be used as a reverse proxy, load balancer, mail proxy and HTTP cache.
nginx.org 置信度 100%VirusTotal 分析
证据与外部报告
PD-20260714-ADA04D Recipient: abuse@reg.ru 您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。