deafblindtradingltd[.]com
“Deafblind Trading Limited - As a firm, our sustained success is based on the ability of our people …”
证据摘要
Analysis of deafblindtradingltd.com indicates this domain was actively impersonating Google as part of a tech support scam. The domain was registered on July 11, 2025, through Atak Domain and resolved to IP 198.12.66.123, hosted on AS36352 (HostPapa) in the US. Nameservers were set to ns1.host-forest.com and ns2.host-forest.com, a pattern consistent with low-cost bulletproof hosting. The SSL certificate was issued by Let's Encrypt (R12), a common choice for malicious domains due to its free and automated issuance. HTTP/3 was detected, a protocol rarely used by legitimate small businesses but occasionally leveraged by threat actors to evade legacy network inspection.
The page title, 'Deafblind Trading Limited - As a firm, our sustained success is based on the ability of our people to be at their best,' does not align with Google's branding or typical support pages, suggesting an attempt to appear as a legitimate corporate entity while delivering scam content. The domain was flagged by one security blocklist and detected by one of 95 vendors on VirusTotal, indicating limited but confirmed malicious activity. PhishDestroy blocked the domain, further corroborating its fraudulent nature. As of July 24, 2026, the domain is offline, though defenders should treat its infrastructure as compromised.
The hosting provider (HostPapa) and registrar (Atak Domain) have historically been slow to respond to abuse reports, so residual risk may persist if the same IP or nameservers are reused. No evidence links this domain to a known phishing kit, but the tech support scam classification is supported by the brand impersonation of Google. Defenders should monitor for re-registration or DNS changes, particularly under the same nameservers or IP range. If observed in logs, this domain should be blocked at the network and endpoint levels, and any associated credentials or session tokens should be invalidated.
Data Coverage
安全信号
威胁响应 Pipeline
阻止列表覆盖
监控中的外部数据源 10 个 · 已存快照 2026年8月12日
检测时间线
-
VirusTotal
0 → 2
-
VirusTotal
2 → 1
已保存的截图
域名情报
技术详情DNS、TLS 名称和时间戳
ICANN OVERSIGHT
认证和 RAA 背景
认证和 RAA 背景
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
VirusTotal 分析
存档证据
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。
检查任意域名
使用存储的阻止列表、WHOIS、DNS 和公共扫描证据进行威胁分析
立即扫描举报网络钓鱼
将可疑域名提交至我们的威胁数据库——保护社区
报告实时威胁动态
最近的网络钓鱼报告和观察到的可用性变化
监控