cl401608-wordpress-czbyj[.]tw1[.]ru
“Домен припаркован в Timeweb”
cl401608-wordpress-czbyj.tw1.ru — لم يتم التحقق منها. انتحال العلامة التجارية: Wordpress; نوع الاحتيال: Brand Impersonation. ملخص الأدلة: VirusTotal 12/91 (ADMINUSLabs, BitDefender, Chong Lua Dao, CyRadar, ESET); Google Safe Browsing flagged; PhishDestroy score 86/100. مسجّل النطاق: TW-Cloud (ASN: 9123).
يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.
The domain cl401608-wordpress-czbyj.tw1.ru has been identified as a high-risk entity due to its involvement in brand impersonation activities, specifically targeting a popular content management system, WordPress. The domain appears to mimic legitimate WordPress sites to deceive users. There is no evidence of specific crypto drainer kits associated with this domain, but its impersonation tactics suggest a focus on potential credential theft or similar fraudulent activities.
Technical analysis of cl401608-wordpress-czbyj.tw1.ru reveals several indicators of malicious intent. VirusTotal reports that 11 out of 95 security vendors have flagged this domain, underscoring its suspect nature. The domain was registered through TW-Cloud, under ASN 9123, and resolves to IP address 92.53.96.105, which is located in Russia (AS9123 JSC TIMEWEB). Google Safe Browsing has flagged this domain as phishing, and it appears on two security blocklists, including PhishDestroy and PhishingDB. The domain's SSL certificate was issued by GlobalSign nv-sa, specifically the GlobalSign GCC R3 DV TLS CA 2020.
Currently, cl401608-wordpress-czbyj.tw1.ru is offline, which mitigates immediate risks. However, the domain's previous online status indicates the potential for significant harm had it remained active. It is essential for users and organizations to remain vigilant against similar domains and employ robust security measures, such as updated anti-phishing tools and regular security awareness training, to mitigate the risks associated with brand impersonation schemes. Continuous monitoring of related IP addresses and registrars is recommended to preemptively identify and neutralize emerging threats.
مسار الاستجابة للتهديدات Pipeline
حالة قوائم الحظر العامة
تحليل VirusTotal
الأدلة المؤرشفة
الأدلة والتقارير الخارجية
هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب