berlusconi-cc[.]to
“Berlusconi || Berlusconi Login || berlusconi-cc.to || Berlusconi Market”
berlusconi-cc.to — المحتوى غير متوفر. نوع الاحتيال: Credential Phishing. ملخص الأدلة: VirusTotal 3/91 (CRDF, Gridinsoft, SOCRadar); PhishDestroy score 71/100. مسجّل النطاق: Government of Kingdom ….
يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.
The domain berlusconi-cc.to is currently active and was registered on October 15, 2025 through the Government of the Kingdom of Tonga. It resolves to the Cloudflare IP address 172.67.70.170, which is geolocated to Canada, and presents a valid SSL certificate issued by Google Trust Services (WE1). An HTTP request to the site returns a 200 status code and the page title reads "Berlusconi || Berlusconi Login || berlusconi-cc.to || Berlusconi Market," indicating an attempt to mimic a legitimate service.
Infrastructure analysis reveals a modern web stack built on Node.js, employing Next.js, Express, React, Bootstrap, and Webpack, with Google Analytics embedded for traffic tracking. The domain is served behind Cloudflare, using the nameservers norman.ns.cloudflare.com and zariyah.ns.cloudflare.com. Reputation services assign a Gridinsoft trust score of 0 out of 100, and VirusTotal reports three detections out of ninety‑five security vendors, confirming malicious indicators. The domain appears on one public blocklist and is actively blocked by PhishDestroy.
Based on the observed page title, low trust score, and vendor detections, the site is classified as a credential phishing operation targeting users who may believe they are accessing a "Berlusconi" service. The evidence points to a deliberate credential‑harvesting campaign, though the limited number of blocklist entries leaves the full scope of distribution uncertain.
Defenders should add berlusconi-cc.to to DNS blocklists and enforce URL filtering to prevent access. Network monitoring should flag any outbound connections to the IP 172.67.70.170, and email security solutions must flag messages containing this domain. Organizations should assume any credentials submitted to the site are compromised and advise users to change affected passwords immediately. Ongoing surveillance of related Cloudflare‑hosted assets is recommended to detect potential expansions of the campaign.
مسار الاستجابة للتهديدات Pipeline
حالة قوائم الحظر العامة
الاستخبارات الجنائية الرقمية
التقنيات · 8 identified
JavaScript runtime built on Chrome V8 engine for server-side development.
Popular CSS framework for responsive, mobile-first web development.
JavaScript library for building user interfaces with component-based architecture.
React framework for production with hybrid static and server rendering.
Web analytics service tracking website traffic and user behavior.
marketingplatform.google.comWeb infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comModule bundler for modern JavaScript applications.
تحليل VirusTotal
الأدلة المؤرشفة
تحليل أداء الموقع
Google PageSpeed Insights — mobile performance audit of berlusconi-cc.to · checked Mar 27, 2026
الأدلة والتقارير الخارجية
PD-20260324-7E2003 Recipient: abuse@tonic.to هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب