Loading...
CARD
INFO
Dominio: pensions.gov.lk
Registrar: N/A
Motori AV recap
- Malevolo: 0
- Sospetto: 0
- Non rilevato: 29
- Innocuo: 65
Analisi Antivirus:
Motori che NON classificano il dominio come harmless:
Analisi DNS
Certificato HTTPS
LEAKS NOTI e MALWARE
Raw data
by HudsonRock
Summary
🧠 Dispositivi infetti: 517
🌐 Utenti compromessi: 483
🧑💼 Utenti aziendali compromessi: 34
🔑 Password aziendali esposte: 45
🔑 Password users esposte: 1120
🧬 Stealer family e conteggio
🏢 Utenze aziendali compromesse (link/conteggio)
🔐 Utenze users compromesse
🛡️ Antivirus rilevati
Dominio: pensions.gov.lk
Registrar: N/A
Motori AV recap
- Malevolo: 0
- Sospetto: 0
- Non rilevato: 29
- Innocuo: 65
Analisi Antivirus:
- Acronis: [harmless] clean
- 0xSI_f33d: [undetected] unrated
- Abusix: [harmless] clean
- ADMINUSLabs: [harmless] clean
- Axur: [undetected] unrated
- Criminal IP: [harmless] clean
- AILabs (MONITORAPP): [harmless] clean
- AlienVault: [harmless] clean
- alphaMountain.ai: [harmless] clean
- AlphaSOC: [undetected] unrated
- Antiy-AVL: [harmless] clean
- ArcSight Threat Intelligence: [undetected] unrated
- AutoShun: [undetected] unrated
- benkow.cc: [harmless] clean
- Bfore.Ai PreCrime: [undetected] unrated
- BitDefender: [harmless] clean
- Bkav: [undetected] unrated
- Blueliv: [harmless] clean
- Certego: [harmless] clean
- Chong Lua Dao: [harmless] clean
- CINS Army: [harmless] clean
- Cluster25: [undetected] unrated
- CRDF: [harmless] clean
- CSIS Security Group: [undetected] unrated
- Snort IP sample list: [harmless] clean
- CMC Threat Intelligence: [harmless] clean
- Cyan: [undetected] unrated
- Cyble: [harmless] clean
- CyRadar: [harmless] clean
- DNS8: [harmless] clean
- Dr.Web: [harmless] clean
- Ermes: [undetected] unrated
- ESET: [harmless] clean
- ESTsecurity: [harmless] clean
- EmergingThreats: [harmless] clean
- Emsisoft: [harmless] clean
- Forcepoint ThreatSeeker: [harmless] clean
- Fortinet: [harmless] clean
- G-Data: [harmless] clean
- GCP Abuse Intelligence: [undetected] unrated
- Google Safebrowsing: [harmless] clean
- GreenSnow: [harmless] clean
- Gridinsoft: [undetected] unrated
- Heimdal Security: [harmless] clean
- Hunt.io Intelligence: [undetected] unrated
- IPsum: [harmless] clean
- Juniper Networks: [harmless] clean
- Kaspersky: [harmless] clean
- Lionic: [harmless] clean
- Lumu: [undetected] unrated
- MalwarePatrol: [harmless] clean
- MalwareURL: [undetected] unrated
- Malwared: [harmless] clean
- Mimecast: [undetected] unrated
- Netcraft: [undetected] unrated
- OpenPhish: [harmless] clean
- Phishing Database: [harmless] clean
- PhishFort: [undetected] unrated
- PhishLabs: [undetected] unrated
- Phishtank: [harmless] clean
- PREBYTES: [harmless] clean
- PrecisionSec: [undetected] unrated
- Quick Heal: [harmless] clean
- Quttera: [harmless] clean
- SafeToOpen: [undetected] unrated
- Sansec eComscan: [undetected] unrated
- Scantitan: [harmless] clean
- SCUMWARE.org: [harmless] clean
- Seclookup: [harmless] clean
- SecureBrain: [undetected] unrated
- SOCRadar: [harmless] clean
- Sophos: [harmless] clean
- Spam404: [harmless] clean
- StopForumSpam: [harmless] clean
- Sucuri SiteCheck: [harmless] clean
- ThreatHive: [harmless] clean
- Threatsourcing: [harmless] clean
- Trustwave: [harmless] clean
- Underworld: [undetected] unrated
- URLhaus: [harmless] clean
- URLQuery: [undetected] unrated
- Viettel Threat Intelligence: [harmless] clean
- VIPRE: [undetected] unrated
- VX Vault: [harmless] clean
- ViriBack: [harmless] clean
- Webroot: [harmless] clean
- Yandex Safebrowsing: [harmless] clean
- ZeroCERT: [harmless] clean
- desenmascara.me: [harmless] clean
- malwares.com URL checker: [harmless] clean
- securolytics: [harmless] clean
- Xcitium Verdict Cloud: [harmless] clean
- zvelo: [undetected] unrated
- ZeroFox: [undetected] unrated
- 0xSI_f33d: [undetected] unrated
- Abusix: [harmless] clean
- ADMINUSLabs: [harmless] clean
- Axur: [undetected] unrated
- Criminal IP: [harmless] clean
- AILabs (MONITORAPP): [harmless] clean
- AlienVault: [harmless] clean
- alphaMountain.ai: [harmless] clean
- AlphaSOC: [undetected] unrated
- Antiy-AVL: [harmless] clean
- ArcSight Threat Intelligence: [undetected] unrated
- AutoShun: [undetected] unrated
- benkow.cc: [harmless] clean
- Bfore.Ai PreCrime: [undetected] unrated
- BitDefender: [harmless] clean
- Bkav: [undetected] unrated
- Blueliv: [harmless] clean
- Certego: [harmless] clean
- Chong Lua Dao: [harmless] clean
- CINS Army: [harmless] clean
- Cluster25: [undetected] unrated
- CRDF: [harmless] clean
- CSIS Security Group: [undetected] unrated
- Snort IP sample list: [harmless] clean
- CMC Threat Intelligence: [harmless] clean
- Cyan: [undetected] unrated
- Cyble: [harmless] clean
- CyRadar: [harmless] clean
- DNS8: [harmless] clean
- Dr.Web: [harmless] clean
- Ermes: [undetected] unrated
- ESET: [harmless] clean
- ESTsecurity: [harmless] clean
- EmergingThreats: [harmless] clean
- Emsisoft: [harmless] clean
- Forcepoint ThreatSeeker: [harmless] clean
- Fortinet: [harmless] clean
- G-Data: [harmless] clean
- GCP Abuse Intelligence: [undetected] unrated
- Google Safebrowsing: [harmless] clean
- GreenSnow: [harmless] clean
- Gridinsoft: [undetected] unrated
- Heimdal Security: [harmless] clean
- Hunt.io Intelligence: [undetected] unrated
- IPsum: [harmless] clean
- Juniper Networks: [harmless] clean
- Kaspersky: [harmless] clean
- Lionic: [harmless] clean
- Lumu: [undetected] unrated
- MalwarePatrol: [harmless] clean
- MalwareURL: [undetected] unrated
- Malwared: [harmless] clean
- Mimecast: [undetected] unrated
- Netcraft: [undetected] unrated
- OpenPhish: [harmless] clean
- Phishing Database: [harmless] clean
- PhishFort: [undetected] unrated
- PhishLabs: [undetected] unrated
- Phishtank: [harmless] clean
- PREBYTES: [harmless] clean
- PrecisionSec: [undetected] unrated
- Quick Heal: [harmless] clean
- Quttera: [harmless] clean
- SafeToOpen: [undetected] unrated
- Sansec eComscan: [undetected] unrated
- Scantitan: [harmless] clean
- SCUMWARE.org: [harmless] clean
- Seclookup: [harmless] clean
- SecureBrain: [undetected] unrated
- SOCRadar: [harmless] clean
- Sophos: [harmless] clean
- Spam404: [harmless] clean
- StopForumSpam: [harmless] clean
- Sucuri SiteCheck: [harmless] clean
- ThreatHive: [harmless] clean
- Threatsourcing: [harmless] clean
- Trustwave: [harmless] clean
- Underworld: [undetected] unrated
- URLhaus: [harmless] clean
- URLQuery: [undetected] unrated
- Viettel Threat Intelligence: [harmless] clean
- VIPRE: [undetected] unrated
- VX Vault: [harmless] clean
- ViriBack: [harmless] clean
- Webroot: [harmless] clean
- Yandex Safebrowsing: [harmless] clean
- ZeroCERT: [harmless] clean
- desenmascara.me: [harmless] clean
- malwares.com URL checker: [harmless] clean
- securolytics: [harmless] clean
- Xcitium Verdict Cloud: [harmless] clean
- zvelo: [undetected] unrated
- ZeroFox: [undetected] unrated
- 0xSI_f33d: undetected (unrated)
- Axur: undetected (unrated)
- AlphaSOC: undetected (unrated)
- ArcSight Threat Intelligence: undetected (unrated)
- AutoShun: undetected (unrated)
- Bfore.Ai PreCrime: undetected (unrated)
- Bkav: undetected (unrated)
- Cluster25: undetected (unrated)
- CSIS Security Group: undetected (unrated)
- Cyan: undetected (unrated)
- Ermes: undetected (unrated)
- GCP Abuse Intelligence: undetected (unrated)
- Gridinsoft: undetected (unrated)
- Hunt.io Intelligence: undetected (unrated)
- Lumu: undetected (unrated)
- MalwareURL: undetected (unrated)
- Mimecast: undetected (unrated)
- Netcraft: undetected (unrated)
- PhishFort: undetected (unrated)
- PhishLabs: undetected (unrated)
- PrecisionSec: undetected (unrated)
- SafeToOpen: undetected (unrated)
- Sansec eComscan: undetected (unrated)
- SecureBrain: undetected (unrated)
- Underworld: undetected (unrated)
- URLQuery: undetected (unrated)
- VIPRE: undetected (unrated)
- zvelo: undetected (unrated)
- ZeroFox: undetected (unrated)
- Axur: undetected (unrated)
- AlphaSOC: undetected (unrated)
- ArcSight Threat Intelligence: undetected (unrated)
- AutoShun: undetected (unrated)
- Bfore.Ai PreCrime: undetected (unrated)
- Bkav: undetected (unrated)
- Cluster25: undetected (unrated)
- CSIS Security Group: undetected (unrated)
- Cyan: undetected (unrated)
- Ermes: undetected (unrated)
- GCP Abuse Intelligence: undetected (unrated)
- Gridinsoft: undetected (unrated)
- Hunt.io Intelligence: undetected (unrated)
- Lumu: undetected (unrated)
- MalwareURL: undetected (unrated)
- Mimecast: undetected (unrated)
- Netcraft: undetected (unrated)
- PhishFort: undetected (unrated)
- PhishLabs: undetected (unrated)
- PrecisionSec: undetected (unrated)
- SafeToOpen: undetected (unrated)
- Sansec eComscan: undetected (unrated)
- SecureBrain: undetected (unrated)
- Underworld: undetected (unrated)
- URLQuery: undetected (unrated)
- VIPRE: undetected (unrated)
- zvelo: undetected (unrated)
- ZeroFox: undetected (unrated)
- Tipo: NS, Valore: ns11.gov.lk
- Tipo: TXT, Valore: google-site-verification=Jslbi8PcYeJJmXpUEbNn4dWHr0xBcJDRB0Q14RDLekI
- Tipo: MX, Valore: mail.pensions.gov.lk
- Tipo: SOA, Valore: ns11.gov.lk
- Tipo: A, Valore: 43.224.124.149
- Tipo: TXT, Valore: v=spf1 a mx a:pensions.gov.lk mx:pensions.gov.lk ip4:203.115.24.109 -all
- Tipo: NS, Valore: ns2.gov.lk
- Tipo: TXT, Valore: google-site-verification=Jslbi8PcYeJJmXpUEbNn4dWHr0xBcJDRB0Q14RDLekI
- Tipo: MX, Valore: mail.pensions.gov.lk
- Tipo: SOA, Valore: ns11.gov.lk
- Tipo: A, Valore: 43.224.124.149
- Tipo: TXT, Valore: v=spf1 a mx a:pensions.gov.lk mx:pensions.gov.lk ip4:203.115.24.109 -all
- Tipo: NS, Valore: ns2.gov.lk
- Emesso da: Sectigo RSA Domain Validation Secure Server CA
- Intestato a: *.pensions.gov.lk
- Valido dal: 2024-07-11 00:00:00
- Valido fino al: 2025-08-11 23:59:59
- Algoritmo firma: RSA
- Versione: V3
- Serial number: 8c9d9a988fd58258e0f8aa0325d4135f
- Intestato a: *.pensions.gov.lk
- Valido dal: 2024-07-11 00:00:00
- Valido fino al: 2025-08-11 23:59:59
- Algoritmo firma: RSA
- Versione: V3
- Serial number: 8c9d9a988fd58258e0f8aa0325d4135f
Summary
🧠 Dispositivi infetti: 517
🌐 Utenti compromessi: 483
🧑💼 Utenti aziendali compromessi: 34
🔑 Password aziendali esposte: 45
🔑 Password users esposte: 1120
🧬 Stealer family e conteggio
RedLine: 198
Lumma: 113
Generic Stealer: 84
Raccoon: 62
StealC: 26
Vidar: 18
Azorult: 9
UNKNOWN: 5
Predator: 1
Lumma: 113
Generic Stealer: 84
Raccoon: 62
StealC: 26
Vidar: 18
Azorult: 9
UNKNOWN: 5
Predator: 1
https://mail.pensions.gov.lk/owa/auth/logon.aspx: 33
https://mail.pensions.gov.lk: 9
https://mail.pensions.gov.lk/owa/auth.owa: 2
https://mail.pensions.gov.lk/owa/auth/expiredpassword.aspx: 1
https://mail.pensions.gov.lk: 9
https://mail.pensions.gov.lk/owa/auth.owa: 2
https://mail.pensions.gov.lk/owa/auth/expiredpassword.aspx: 1
-
https://sathkara.pensions.gov.lk/pms/index.php/login: 212
http://www.sathkara.pensions.gov.lk/pms/index.php/login: 143
https://service.pensions.gov.lk/pms/index.php/login: 119
https://sathkara.pensions.gov.lk: 83
https://sathkara.pensions.gov.lk/v3: 65
https://••••••••.pensions.gov.lk/•••/•••••.•••/••••••: 61
http://••••••••.pensions.gov.lk/•••/•••••.•••/•••••: 60
https://•••••••.pensions.gov.lk/••••: 44
http://•••.••••••••.pensions.gov.lk: 35
https://•••.••••••••.pensions.gov.lk/•••/•••••.•••/•••••: 32
http://•••••••••••.pensions.gov.lk/••••••••: 21
http://•••••••••••.pensions.gov.lk: 17
http://••••••••.pensions.gov.lk/•••/•••••.•••/••••••: 15
https://••••••••.pensions.gov.lk/••••: 15
https://•••••••.pensions.gov.lk: 13
http://••••••••.pensions.gov.lk: 13
https://•••••••••••.pensions.gov.lk/••••••••: 13
https://•••••••••••.pensions.gov.lk: 12
https://•••••••.pensions.gov.lk/••••••••: 10
https://•••••••.pensions.gov.lk: 9
http://•••.••••••••.pensions.gov.lk/•••/•••••.•••/•••••/••••••••: 8
https://•••••••••••.pensions.gov.lk/••••••••/: 7
https://••••••••.pensions.gov.lk/: 7
https://•••••••.pensions.gov.lk/•••/•••••.•••/•••••/•••••••••: 7
http://••••••.pensions.gov.lk:••••/•••••.•••: 6
http://•••.••••••••.pensions.gov.lk/••: 6
http://••••••.pensions.gov.lk:••••/: 5
http://••••••.pensions.gov.lk/••••••/: 5
http://••••••.pensions.gov.lk:••••/•••••.•••;••••••••••=••••••••••••••••••••••••••••••••: 5
http://••••••••.pensions.gov.lk:••••/: 5
http://••••••••.pensions.gov.lk/•••-•••/: 5
http://•••.••••••••.pensions.gov.lk/: 5
https://••••••.pensions.gov.lk:••••/: 5
https://••••••••.pensions.gov.lk:••••/: 5
https://•••••••.pensions.gov.lk/•••••••••: 5
http://•••••••••••.pensions.gov.lk/: 4
https://••••••••.pensions.gov.lk/••••/: 4
https://••••••••.pensions.gov.lk/••/: 4
http://•••••••••.pensions.gov.lk/••••••/••••••/••••••••/•: 3
https://•••••••••.pensions.gov.lk/••••••/••••••/••••••••/•: 3
http://•••••••••••.pensions.gov.lk/•••••••••/: 2
http://•••••••••••.pensions.gov.lk/••••••••/: 2
http://••••••••.pensions.gov.lk/•••/•••••.•••/•••••/••••••••: 2
http://•••.••••••••.pensions.gov.lk/•••/•••••.•••/••••••: 2
https://••••••.pensions.gov.lk:••••/•••••.•••: 1
https://••••••••.pensions.gov.lk/•••/•••••.•••/•••••/••••••••: 1
https://•••••••.pensions.gov.lk/••••••••••: 1
http://••••••••.pensions.gov.lk/••••_••••: 1
https://•••••••.pensions.gov.lk/•••••••/•••••.•••/•••••: 1
http://•••••••••••.pensions.gov.lk/••••••: 1
http://•••.•••••••••••.pensions.gov.lk/••••••: 1
http://••••••.pensions.gov.lk/••••••: 1
http://••••••.pensions.gov.lk:••••/•••••.•••;••••••••••=••••••••••••••••••••••••••••••••: 1
http://••••••.pensions.gov.lk:••••: 1
http://••••••••.pensions.gov.lk/•••-•••: 1
http://••••••••.pensions.gov.lk:••••: 1
https://••••••.pensions.gov.lk:••••: 1
https://••••••••.pensions.gov.lk:••••: 1
http://•••••••••••.pensions.gov.lk/•••••••••: 1
http://••••••.pensions.gov.lk:••••/•••_••: 1
https://•••.••••••••.pensions.gov.lk: 1
https://•••••••.pensions.gov.lk/••: 1
Kaspersky Security Cloud: 1
Reason Cybersecurity: 1
Windows Defender: 8
ESET Security: 1
Avira Security: 1
ESET Firewall: 1
Not Found: 9
360 Total Security: 1
Reason Cybersecurity: 1
Windows Defender: 8
ESET Security: 1
Avira Security: 1
ESET Firewall: 1
Not Found: 9
360 Total Security: 1