cs880817-wordpress-f5a04[.]tw1[.]ru
“Домен припаркован в Timeweb”
cs880817-wordpress-f5a04.tw1.ru — لم يتم التحقق منها. انتحال العلامة التجارية: Wordpress; نوع الاحتيال: Brand Impersonation. ملخص الأدلة: VirusTotal 14/91 (ADMINUSLabs, alphaMountain.ai, BitDefender, CyRadar, ESET); Google Safe Browsing flagged; CF Radar malicious; PhishDestroy score 97/100. مسجّل النطاق: TW-Cloud (ASN: 9123).
يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.
This domain, cs880817-wordpress-f5a04.tw1.ru, is actively flagged as a high-risk brand impersonation threat targeting WordPress. Analysis indicates the domain is registered through TW-Cloud (ASN 9123) and currently resolves to the IPv6 address 2a03:6f00:1::5c35:6069. The page title, 'Домен припаркован в Timeweb,' suggests it may be hosted on a parked domain service, though the exact content remains unanalyzed. Security vendors have detected malicious indicators, with 12 out of 95 engines on VirusTotal flagging the domain, and it appears on two security blocklists, including PhishDestroy and PhishingDB. The domain is explicitly categorized as engaging in social engineering, as confirmed by Google Safe Browsing. Its Gridinsoft trust score of 0/100 and Scamadviser trust score of 1/100 further corroborate its high-risk classification. The SSL certificate is issued by GlobalSign nv-sa, which does not mitigate the underlying threat but may lend a superficial appearance of legitimacy. No specific phishing kit or payload has been identified in the available data, leaving the exact attack vector uncertain. Defenders should treat this domain as an active threat. Immediate action includes blocking the domain and its resolving IP at the network perimeter, as well as monitoring for any internal connections to it. Given the domain's association with brand impersonation and social engineering, user awareness training may be warranted to prevent potential credential harvesting or malware distribution. The domain remains active as of July 12, 2026, and should be prioritized for further investigation if any internal systems have interacted with it. No evidence suggests this is part of a larger campaign, but its registration through a known hosting provider warrants scrutiny of related infrastructure.
مؤشرات الأمان
استخبارات أمن الشبكات
مسار الاستجابة للتهديدات Pipeline
حالة قوائم الحظر العامة
تحليل VirusTotal
الأدلة المؤرشفة
الأدلة والتقارير الخارجية
هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب