sdg661[.]it
“Welcome aboard”
证据摘要
sdg661.it was registered on June 16, 2025 through the registrar 1 Api GmbH and is hosted on Cloudflare infrastructure (AS13335) with the IP address 104.21.7.184 located in the United States. The domain resolves to a Cloudflare‑managed server that presented a TLS certificate issued by Google Trust Services under the WE1 designation, and the service was observed supporting HTTP/3. The only visible element on the site, as captured before it was taken offline, was the page title “Welcome aboard”. The site was subsequently taken offline and is currently listed as blocked by the PhishDestroy platform, and it appears on a single external security blocklist.
VirusTotal scans reported that two out of ninety‑five security scanners flagged the domain, indicating a modest but non‑trivial detection rate. No additional intelligence such as Safe Browsing, Open Threat Exchange, or detailed malware kit attribution was available at the time of analysis. The limited evidence points to a generic phishing campaign that likely leverages the welcoming title to lure victims into a credential‑harvesting flow, although the exact target brand or service cannot be confirmed from the collected data.
Defenders should add the domain and its associated IP address to deny‑list rules in DNS filtering and web proxy solutions, monitor for outbound connections to the Cloudflare IP range, and ensure that endpoint protection tools reference the current VirusTotal detection status. Continuous monitoring of the registrar 1 Api GmbH for new domains with similar characteristics and periodic re‑query of blocklist feeds is recommended to catch any re‑activation attempts. Because the site is already offline, immediate incident response is not required, but awareness of the pattern may help prevent future impersonation attempts that reuse the same infrastructure.
Data Coverage
威胁响应 Pipeline
阻止列表覆盖
监控中的外部数据源 10 个 · 已存快照 2026年8月11日
检测时间线
VirusTotal 分析
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。
检查任意域名
使用存储的阻止列表、WHOIS、DNS 和公共扫描证据进行威胁分析
立即扫描举报网络钓鱼
将可疑域名提交至我们的威胁数据库——保护社区
报告实时威胁动态
最近的网络钓鱼报告和观察到的可用性变化
监控