Notification and current-status evidence
The sent-report ledger records the first outgoing report at .
The recorded recipient is abuse@living-bots.net.
The latest stored availability evidence still shows the domain reachable; 6 months has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
fahri-kayran[.]de
“Fahri Kayran - Das bin ich!”
fahri-kayran.de — 未验证. 证据摘要: VirusTotal 10/91 (ADMINUSLabs, alphaMountain.ai, BitDefender, CyRadar, Forcepoint ThreatSeeker); PhishDestroy score 93/100. 注册商: Living-bots.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
fahri-kayran.de was registered on 21 February 2026 through the registrar Living-bots and is hosted on an address in Germany (45.88.111.197, AS44486 synlinq.de). The authoritative nameservers are ns1.dnslinq.de and ns2.dnslinq.de. The site presents a TLS certificate issued by Let’s Encrypt (R13) and returns an HTTP 301 redirect. The page title returned by the server is “Fahri Kayran - Das bin ich!”. Automated analysis identified a stack that includes Plesk, Apache HTTP Server, Unpkg, OWL Carousel, jQuery and Font Awesome. The Gridinsoft trust score is 0 out of 100, indicating a lack of reputation.
VirusTotal has recorded five detections out of ninety‑three scanners, and the domain appears on one public phishing blocklist as well as the PhishDestroy blocklist. AlienVault OTX lists the domain in a single threat‑intel pulse. The risk level is classified as high and the threat type is generic phishing; the domain remains active as of the report date 24 July 2026. The available evidence confirms that the infrastructure is newly created, uses common web‑hosting components, and has already attracted modest detection from security vendors. However, the specific phishing payload, targeted victim set, and any credential‑harvesting pages have not been observed, leaving the exact attack vector uncertain. Defenders should prioritize immediate blocking of the domain and its resolved IP address at perimeter firewalls and proxy layers.
Adding the domain to internal URL filtering and threat‑intelligence feeds will ensure continued visibility. Continuous monitoring of the IP range owned by AS44486 and periodic re‑scans with VirusTotal or similar platforms are recommended to capture any escalation in malicious activity. Organizations that rely on the listed web technologies should be aware of potential abuse of these components for drive‑by or credential‑stealing scripts.
威胁响应 Pipeline
公共封禁名单状态
所用技术 · 6 identified
Most widely used open-source HTTP server software.
Fast CDN for everything on npm — serves raw files from npm packages.
Touch-enabled jQuery plugin for responsive carousel sliders.
Fast, small JavaScript library simplifying HTML manipulation, event handling, and Ajax.
Icon font library.
VirusTotal 分析
存档证据
网站性能分析
Google PageSpeed Insights — mobile performance audit of fahri-kayran.de · checked Mar 2, 2026
证据与外部报告
PD-20260202-8F8F16 Recipient: abuse@living-bots.net 您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。