hofaso[.]do
“.”
hofaso.do — 未验证. 品牌冒充:Telegram; 诈骗类型:Impersonation. 证据摘要: VirusTotal 3/91 (alphaMountain.ai, CRDF, Gridinsoft); PhishDestroy score 71/100.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
The domain hofaso.do was registered on 21 February 2026 and is presently taken offline. DNS resolution points to the IPv4 address 185.231.33.130, which is announced by AS211720 belonging to Datashield, Inc. and geolocated to South Carolina, United States. The host presents an SSL certificate identified as R12, indicating the use of a short‑lived or self‑signed certificate typical of malicious infrastructure. Reputation services have flagged the domain: three of ninety‑three VirusTotal scanners reported detections, and the site is listed on a single external blocklist.
Additionally, the PhishDestroy feed has actively blocked the domain. The page title returned by HTTP queries is a single period (“.”), providing no insight into the intended impersonated brand or lure technique. No public evidence of the landing page content, credential‑capture forms, or redirect behavior is available, and the site does not appear to be serving active traffic at the time of analysis. Given the limited but concrete indicators—recent registration, dedicated IP under a known hosting ASN, low‑level TLS certificate, and multi‑vendor detection—it is prudent for defensive teams to treat hofaso.do as a malicious phishing vector until further remediation.
Organizations should add the domain and its resolving IP address to network‑level deny lists, enforce DNS filtering that incorporates the observed blocklist entry, and ensure that web‑proxy and email security gateways reference the PhishDestroy feed. Continuous monitoring of the IP space owned by Datashield, Inc. may reveal additional related artifacts. Because the site is offline, active response options such as sinkholing are not applicable, but threat‑intel correlation with other observed campaigns that share the same ASN or certificate profile could surface broader attribution.
威胁响应 Pipeline
公共封禁名单状态
VirusTotal 分析
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。