cx718554-wordpress-f7iuo[.]tw1[.]ru
“Домен припаркован в Timeweb”
cx718554-wordpress-f7iuo.tw1.ru — لم يتم التحقق منها. انتحال العلامة التجارية: Wordpress; نوع الاحتيال: Brand Impersonation. ملخص الأدلة: VirusTotal 11/91 (ADMINUSLabs, alphaMountain.ai, BitDefender, ESET, Fortinet); CF Radar malicious; PhishDestroy score 88/100. مسجّل النطاق: TW-Cloud (ASN: 9123).
يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.
The domain cx718554-wordpress-f7iuo.tw1.ru is confirmed to pose a specific threat of brand impersonation, targeting WordPress users. Analysis indicates that the domain was used to mislead users into believing it is an official WordPress site, potentially to harvest login credentials or other sensitive information. The domain is currently offline, but the risk remains elevated due to its previous activities and the number of security vendors that flagged it.
Infrastructure analysis reveals that this domain was registered through TW-Cloud (ASN: 9123) and resolves to the IP address 92.53.96.105, located in Russia (RU) under the Autonomous System AS9123 JSC TIMEWEB. On VirusTotal, 12 out of 95 security vendors flagged this domain as malicious, indicating a significant level of suspicion among security experts. Additionally, the domain appears on 2 security blocklists: PhishDestroy and PhishingDB. The page title found when the domain was active was 'Домен припаркован в Timeweb', which translates to 'Domain parked at Timeweb', suggesting that the domain was parked or not actively being used for legitimate purposes during the analysis.
If users have visited this domain, they should immediately check their WordPress accounts for any unauthorized activity. It is recommended to change passwords and enable two-factor authentication (2FA) if it is not already activated. Users should also monitor their accounts for any unusual transactions or changes and report any suspicious activity to their hosting provider or WordPress support. Security professionals are advised to block this domain and similar IP addresses to prevent further potential compromises.
مؤشرات الأمان
استخبارات أمن الشبكات
مسار الاستجابة للتهديدات Pipeline
حالة قوائم الحظر العامة
تحليل VirusTotal
الأدلة المؤرشفة
الأدلة والتقارير الخارجية
هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب