ref0107azpvkl[.]unifiedsrvgrid[.]com
“Business Help Center”
ref0107azpvkl.unifiedsrvgrid.com — 内容不可用. 诈骗类型:Credential Phishing. 证据摘要: VirusTotal 10/91 (alphaMountain.ai, CRDF, Emsisoft, Fortinet, G-Data); URLQuery 2 det.; Spamhaus DBL_PHISH; CF Radar malicious; PhishDestroy score 93/100. 注册商: GMO Internet.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
This domain, ref0107azpvkl.unifiedsrvgrid.com, is actively engaged in credential harvesting phishing operations. Analysis indicates the site mimics legitimate login interfaces to deceive users into submitting usernames, passwords, and potentially multi-factor authentication codes. Such attacks are commonly used to gain unauthorized access to email accounts, financial platforms, or corporate systems, leading to data breaches, identity theft, or further compromise of connected services. The site may also distribute malware under the guise of required software updates or security plugins, increasing the risk of device infection and lateral movement within networks. Infrastructure analysis reveals multiple technical indicators confirming malicious intent. The domain resolves to IP address 104.21.69.206 and is secured with an SSL certificate issued by Google Trust Services, a tactic frequently employed to lend false legitimacy. As of the latest scan, 9 out of 95 security vendors on VirusTotal have flagged the domain as malicious, with signatures detecting phishing behavior, fraudulent login forms, and suspicious JavaScript patterns. The domain was registered on June 30, 2026, through GMO Internet, Inc., and remains operational despite detection, suggesting ongoing abuse. The use of a subdomain under unifiedsrvgrid.com, a hosting provider known for transient phishing infrastructure, further supports the assessment of deliberate malicious activity. Users who have visited ref0107azpvkl.unifiedsrvgrid.com or entered credentials on the site should take immediate action to mitigate risk. First, reset passwords for any accounts accessed after visiting the domain, prioritizing email, financial, and work-related services. Enable multi-factor authentication using app-based or hardware tokens, not SMS, to reduce the risk of credential replay attacks. Scan the device used to access the site with updated security software to detect and remove any downloaded malware. Monitor accounts for unauthorized transactions, sent emails, or configuration changes, such as email forwarding rules or password recovery options. If corporate credentials were exposed, report the incident to internal security teams to initiate incident response protocols, including log review and network isolation if necessary. Finally, consider placing a fraud alert or credit freeze with relevant bureaus if financial or personal data was compromised.
网络安全情报
威胁响应 Pipeline
公共封禁名单状态
已保存的截图
域名情报
技术细节DNS、SSL SAN、时间戳
ICANN OVERSIGHT
Registration: unifiedsrvgrid.com
认证和 RAA 背景
认证和 RAA 背景
Registrar accreditation and DNS abuse obligations
For the registrable domain unifiedsrvgrid.com behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
所用技术 · 2 identified
Cloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com 置信度 100%HTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 置信度 100%VirusTotal 分析
网站性能分析
Google PageSpeed Insights — mobile performance audit of ref0107azpvkl.unifiedsrvgrid.com · checked Jul 3, 2026
证据与外部报告
PD-20260703-689E51 Recipient: abuse@internet.gmo 您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。