edagvusvussupplion[.]us025[.]jlabogados[.]com[.]mx
“ushort.info”
edagvusvussupplion.us025.jlabogados.com.mx — 未验证. 诈骗类型:Generic Phishing. 证据摘要: VirusTotal 14/91 (BitDefender, CyRadar, ESET, Emsisoft, Forcepoint ThreatSeeker); Google Safe Browsing flagged; PhishDestroy score 98/100. 注册商: AKKY ONLINE SOLUTIONS.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
Analysis of the domain edagvusvussupplion.us025.jlabogados.com.mx indicates it is a high-risk phishing site, currently offline as of July 24, 2026. The domain was registered on March 6, 2026, through AKKY ONLINE SOLUTIONS, S.A. DE C.V., a registrar frequently associated with abusive domains. Infrastructure analysis reveals the domain resolves to the IP address 104.21.63.158, hosted on AS46606 (Unified Layer) in the United States. Nameservers point to HostGator Mexico (ns78.hostgator.mx at 162.241.60.165 and ns79.hostgator.mx at 162.241.60.166), a hosting provider commonly leveraged for both legitimate and malicious campaigns. The page title, 'ushort.info,' suggests the phishing site may have impersonated or redirected users to a URL-shortening service, though the exact content of the page remains unconfirmed due to its offline status.
Google Safe Browsing has flagged the domain for social engineering, aligning with typical phishing behavior. Detection data from VirusTotal shows 15 of 94 security vendors marked the domain as malicious, while PhishDestroy has explicitly blocked it. The domain appears on at least one security blocklist, further corroborating its malicious classification. The SSL certificate is issued by Let's Encrypt (R12), a common choice for both legitimate and phishing sites due to its free and automated issuance process. The HTTP status code 200, observed prior to takedown, indicates the site was operational and served content without server-side errors.
While the specific phishing kit or targeted brand is not identified in available intelligence, the combination of registrar, hosting provider, detection counts, and Safe Browsing flags strongly supports its classification as a phishing domain. Defenders should treat this domain as compromised and maintain its blocklist status. Organizations using threat intelligence feeds are advised to verify whether internal systems have logged connections to 104.21.63.158 or the domain itself.
威胁响应 Pipeline
公共封禁名单状态
已保存的截图
域名情报
技术细节DNS、SSL SAN、时间戳
VirusTotal 分析
存档证据
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。