captcha[.]zlon8[.]cc
ملخص الأدلة
Analysis of the domain captcha.zlon8.cc indicates it was actively used for credential phishing before being taken offline. The domain was registered on February 12, 2026, through NICENIC INTERNATIONAL GROUP CO., LIMITED, and resolved to the IP address 178.20.210.32, hosted on AS210006 (Shereverov Marat Ahmedovich) in Finland. At the time of assessment, the domain returned an HTTP 403 status, suggesting access was restricted or the server was configured to deny requests. Nameservers were set to hold1.suspendedaccount.com and hold2.suspendedaccount.com, which are commonly associated with suspended or compromised infrastructure.
Technical indicators reveal the use of Nginx as the web server and HSTS enforcement, which may have been employed to lend legitimacy to the phishing site. The SSL certificate was issued by Let's Encrypt (YE1), a common choice for both legitimate and malicious domains due to its accessibility. Eight of 91 security vendors on VirusTotal flagged the domain as malicious, and it appeared on at least one security blocklist. The domain was blocked by PhishDestroy prior to being taken offline.
The exact content or targeted brand remains unconfirmed, as no page title, scam type, or brand target was provided in available intelligence. Defenders should treat this domain as part of a broader phishing campaign and monitor for related infrastructure. Network-level blocking of the IP 178.20.210.32 and associated domains registered through the same registrar may disrupt further activity. Historical DNS and SSL certificate logs should be reviewed for additional indicators of compromise.
Data Coverage
استخبارات أمن الشبكات
مسار الاستجابة للتهديدات Pipeline
تغطية قوائم الحظر
١٠ مصادر خارجية مراقبة · لقطة محفوظة 11/08/2026
المخطط الزمني للاكتشاف
-
Cloudflare Radar
تم حفظ فحص Cloudflare Radar · فتح الفحص
التقنيات
حُدّدَت تقنيتان عاليتا الثقة
تحليل VirusTotal
هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب