VirusTotal
10 / 91
“Service Suspended”
ozakagi.network — 最后已知的活跃状态 (HTTP 200). 诈骗类型:Account Takeover. 证据摘要: VirusTotal 10/91 (alphaMountain.ai, BitDefender, Chong Lua Dao, CyRadar, Forcepoint ThreatSeeker); 3 external blocklist matches (Polkadot, Enkrypt, Codeesura); PhishDestroy score 100/100. 注册商: NameSilo.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
The domain ozakagi.network is identified as a generic phishing infrastructure specifically designed to target users of cryptocurrency platforms. Analysis indicates the domain is currently offline, though it previously displayed a 'Service Suspended' page title, a common tactic to evade immediate detection while maintaining operational readiness. No direct brand impersonation has been confirmed, but the domain's characteristics align with phishing campaigns aimed at stealing credentials or financial information from users interacting with decentralized services. Infrastructure analysis reveals the domain was registered on February 21, 2026, through NameSilo, LLC, a registrar frequently associated with high-risk domains. It resolves to the IP address 216.24.57.7, hosted on AS397273 Render in the United States. The domain is flagged by 12 of 95 security vendors on VirusTotal, indicating a significant consensus among threat intelligence providers regarding its malicious nature. Additionally, ozakagi.network appears on four security blocklists and is actively blocked by multiple cryptocurrency-focused security tools, including PhishDestroy, Polkadot, Enkrypt, and Codeesura. The SSL certificate is classified as WE1, a low-trust indicator often observed in phishing or fraudulent domains. Current status confirms the domain has been taken offline, likely due to enforcement actions or the conclusion of its operational lifecycle. However, the infrastructure remains a documented threat, and users should treat any prior interactions with the domain as compromised. Organizations and individuals are advised to block the domain and its associated IP address at the network level. Cryptocurrency users should verify the legitimacy of any service requesting credentials or transactions, particularly those linked to decentralized platforms. Monitoring for similar domains registered through NameSilo or hosted on Render’s infrastructure may help preempt future threats.
针对该主机的爬虫与浏览器观察记录,以及针对“Keitaro”式流量分配系统的实时指纹检测。
openresty扫描说明: alive_content: raw=ok; http=200; via=https_direct; server=openresty
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Edge-IP 声誉不属于此域。
ns2.vercel-dns.comLocation describes the IP network.
b334091452d53a1b084e2774f1a0a4866bab10678174e6b651b5335a4201c704Saved certificate metadata. Certificate dates without a timezone are shown as stored. Transport encryption does not establish that the site is trustworthy.
11 recorded events. These records describe collected evidence, outgoing notifications and publication; they do not confirm a complete investigation or a takedown.
We scan suspicious URLs, inspect public results and send evidence through the appropriate abuse-reporting channels. The dated events above show what is recorded for this domain. The directory below explains the wider workflow.
Capture the rendered page, requests and visible infrastructure.
Compare the available engine results and retain the analysis timestamp.
Check whether Google currently lists the URL as unsafe.
Inspect a public scan and its recorded network and classification data.
Look for indicator references and related community intelligence.
Compare archived captures and preserve historical context.
Look for matching indicators and associated threat records.
Inspect certificate records and related hostnames.
Compare security resolver responses and record observed blocking.
Inspect the public DNS, TLS, HTTP and technology surface.
Security services used for scanning, reputation checks and reporting are listed below. A service being listed is not evidence that it received, accepted or acted on this particular domain. Recorded submissions appear in the notification history above.
由 1 名社区成员报告;首次发现于 2025年10月3日
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。
选择您所在的国家/地区以获取 官方网络犯罪联系人 或 创建投诉草稿 →。
Template-based draft · optional AI wording assistance requires separate consent