hirortex[.]de
hirortex.de 网络钓鱼与安全检查
“Hirortex”
hirortex.de — 内容不可用 (HTTP 502). 品牌冒充:Argent; 诈骗类型:Brand Impersonation. 证据摘要: VT 16/93 (alphaMountain.ai, BitDefender, Certego, Chong Lua Dao, CRDF); URLQuery 0; URLScan malicious; GSB flagged; BL 0; PD 100/100.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
hirortex.de entered the PhishDestroy evidence set on Jan 28, 2026. Stored content metadata identifies Argent as the apparent target. Content analysis also recorded brand signals for Binance, Coinbase, Ethereum, Kraken, Revolut, and Sei. The stored content classification is brand impersonation. The assembled evidence scores 100/100 (critical).
Three independent sources are positive: VirusTotal, Google Safe Browsing, and URLScan. VirusTotal recorded 16 detections among 93 engines: alphaMountain.ai, BitDefender, Certego, Chong Lua Dao, CRDF, CyRadar, Fortinet, G-Data, Google Safebrowsing, Gridinsoft, Lionic, Seclookup, SOCRadar, Sophos, VIPRE, Webroot on Feb 23, 2026 at 12:17 UTC. Google Safe Browsing flagged the domain: Social Engineering on Feb 25, 2026 at 20:32 UTC. URLScan returned a malicious verdict with score 100 on Mar 28, 2026 at 12:19 UTC. The evidence is not unanimous. AlienVault OTX listed 1 community pulse reference (not vendor detections) on Mar 1, 2026 at 10:50 UTC. The external blocklist snapshot contained no matches on Aug 7, 2026 at 14:20 UTC. URLQuery recorded no positive detection. PhishStats returned no feed match on Mar 2, 2026 at 11:04 UTC.
HTTP 502 was recorded on Aug 7, 2026 at 01:17 UTC; content was unavailable. At collection time, the hostname resolved to 188.114.97.3 on AS13335 (CLOUDFLARENET - Cloudflare, Inc., US). The associated network metadata labels the endpoint as AS13335 Cloudflare, Inc. in San Francisco, US. The stored server header is cloudflare. Captured page title: “Hirortex”. DOM analysis completed on Apr 23, 2026 at 07:21 UTC; stored DOM score 10/100. The evidence archive retains 2 visual captures from PhishDestroy and URLScan. IoC extraction completed on Aug 2, 2026 at 04:14 UTC; stored 0 format-validated wallet addresses and 0 Telegram indicators.
Taken together, the page content and independent findings support classifying this hostname as Argent-themed brand impersonation.
威胁响应 Pipeline
公共封禁名单状态
VirusTotal 分析
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。