MALICIOUS — HIGH
confirmation-id71124[.]com
This domain, confirmation-id71124.com, is identified as a credential theft phishing operation.
- VirusTotal
- 2/91
- Blocklists
- No stored match
- التوفر
- المحتوى غير متوفر · HTTP 502
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
confirmation-id71124.com — المحتوى غير متوفر (HTTP 502). نوع الاحتيال: Credential Phishing. ملخص الأدلة: VirusTotal 2/91 (alphaMountain.ai, SOCRadar); PhishDestroy score 65/100. مسجّل النطاق: Hello Internet.
يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.
Evidence Analysis
This domain, confirmation-id71124.com, is identified as a credential theft phishing operation. Analysis indicates the site impersonates authentication prompts, likely targeting users with fake verification requests to harvest login credentials. No specific brand impersonation or cryptocurrency drainer components were confirmed, but the generic phishing framework aligns with credential harvesting tactics observed in similar campaigns. Infrastructure analysis reveals the domain was registered on June 12, 2026, through Hello Internet Corp. It resolves to the IP address 104.21.76.195 and employs Cloudflare with HTTP/3 support, a common obfuscation tactic to evade detection. The domain appears on 2 security blocklists and is flagged by 17 out of 95 security vendors on VirusTotal. AlienVault OTX records it in 6 threat intelligence pulses, while Gridinsoft assigns a trust score of 0/100. The page title, 'Just a moment...', suggests the use of Cloudflare's interstitial page, likely to mask malicious content during initial access. The domain is currently offline, reducing immediate risk of active credential theft. However, residual risk persists due to the domain's recent registration and prior malicious activity. Response actions should include monitoring for re-registration or IP reuse, as well as alerting users who may have interacted with the domain. Organizations are advised to block the domain and associated IP at the network level and review logs for connections to 104.21.76.195 during the period of activity.
نطاق تغطية البيانات12 recorded checks
استخبارات أمن الشبكات
مسار الاستجابة للتهديدات Pipeline
حالة قوائم الحظر العامة
لقطة محفوظة
معلومات النطاق
التفاصيل الفنيةDNS، أسماء المجال البديلة (SAN) في بروتوكول SSL، الطوابع الزمنية
ICANN OVERSIGHT
الاعتماد وسياق RAA
الاعتماد وسياق RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
التقنيات · 2 identified
Cloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com ثقة 100٪HTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org ثقة 100٪تحليل VirusTotal
تحليل أداء الموقع
Google PageSpeed Insights — mobile performance audit of confirmation-id71124.com · checked Jun 25, 2026
الأدلة والتقارير الخارجيةIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.