cgl[.]iwp[.]mybluehost[.]me
“Welcome — Próximamente”
cgl.iwp.mybluehost.me — لم يتم التحقق منها. ملخص الأدلة: VirusTotal 6/91 (alphaMountain.ai, Chong Lua Dao, Emsisoft, Gridinsoft, LevelBlue); CF Radar malicious; PhishDestroy score 78/100. مسجّل النطاق: Domain.com - Network S….
يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.
cgl.iwp.mybluehost.me is currently active and has been classified as a generic phishing site. The domain was registered on October 05 2016 through Domain.com – Network Solutions, LLC and is hosted on the MyBluehost infrastructure, using the authoritative nameservers ns1.mybluehost.me and ns2.mybluehost.me. DNS resolution points to the IPv4 address 69.6.192.12, which belongs to an Oracle Corporation network (AS31898) located in Spain. The server presents a Sectigo Limited‑issued DV certificate (Sectigo Public Server Authentication CA R36), indicating that TLS is enabled but offering no additional trust.
HTTP requests receive a 302 redirect response, a common technique used to forward victims to malicious payloads or credential‑harvesting pages. The public page title returned by the web server is “Welcome — Próximamente”, and no further content has been collected, leaving the exact phishing landing page unknown. Threat intelligence sources have placed the domain on a single security blocklist and it is explicitly blocked by the PhishDestroy service. VirusTotal analysis reports that 8 of 93 scanned security vendors flag the domain as malicious, reinforcing the suspicion of phishing activity.
The limited number of blocklist appearances suggests that the infrastructure may be newly repurposed or that detection coverage is still expanding. Defenders should consider immediate network‑level blocking of the domain and its resolved IP address, enforce TLS inspection to capture any redirected traffic, and monitor for new sub‑domains under the same registrar and nameserver pair. Continuous re‑scanning with multi‑vendor engines is advised to detect any changes in the detection ratio. Because the underlying content has not been fully enumerated, threat hunters should collect the actual response payloads after following the 302 redirect to confirm the credential‑stealing mechanism and to enrich detection signatures.
استخبارات أمن الشبكات
مسار الاستجابة للتهديدات Pipeline
حالة قوائم الحظر العامة
تحليل VirusTotal
الأدلة المؤرشفة
الأدلة والتقارير الخارجية
هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب