elfcosmeticcs[.]com
فحص التصيد والأمان للنطاق elfcosmeticcs.com
“e.l.f. Cosmetics: Affordable Makeup & Skincare – Cruelty Free | e.l.f. Cosmetics”
elfcosmeticcs.com — المحتوى غير متوفر (HTTP 502). نوع الاحتيال: Generic Phishing. ملخص الأدلة: VirusTotal 6/91 (alphaMountain.ai, CRDF, Forcepoint ThreatSeeker, Gridinsoft, PhishFort); PhishDestroy score 78/100. مسجّل النطاق: Dynadot.
يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.
Evidence Analysis
This domain is flagged for credential phishing, a threat type targeting user authentication data through deceptive login interfaces. Analysis indicates an elevated risk level due to its recent creation, blocklist presence, and detection by multiple security engines. The domain is designed to mimic legitimate cosmetic retail sites, increasing the likelihood of successful social engineering attacks against unsuspecting users. Infrastructure analysis reveals the domain elfcosmeticcs.com was registered on April 22, 2026, through Dynadot Inc. It resolves to the IP address 62.106.90.234 and appears on one security blocklist, specifically PhishDestroy. VirusTotal reports 6 out of 95 security vendors flagging the domain as malicious, while Gridinsoft assigns a trust score of 0/100. The page title, "e.l.f. Cosmetics: Affordable Makeup & Skincare – Cruelty Free | e.l.f. Cosmetics," closely mirrors the branding of a legitimate retailer, further supporting the phishing classification. Mitigation steps for credential phishing threats include immediate domain blocking at the network perimeter and endpoint levels. Network administrators should add the domain and its associated IP (62.106.90.234) to deny lists in firewalls, proxies, and DNS filtering systems. Security teams should conduct retrospective log analysis to identify any prior interactions with the domain, particularly focusing on authentication attempts or form submissions. User awareness training should emphasize the risks of entering credentials on unverified sites, even if the page design appears legitimate. Additionally, multi-factor authentication (MFA) should be enforced for all accounts to reduce the impact of credential theft.
نطاق تغطية البيانات12 recorded checks
استخبارات أمن الشبكات
مسار الاستجابة للتهديدات Pipeline
حالة قوائم الحظر العامة
لقطة محفوظة
معلومات النطاق
التفاصيل الفنيةDNS، أسماء المجال البديلة (SAN) في بروتوكول SSL، الطوابع الزمنية
ICANN OVERSIGHT
الاعتماد وسياق RAA
الاعتماد وسياق RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
تحليل VirusTotal
الأدلة والتقارير الخارجيةIndependent lookups and source reports
PD-20260611-BD8117 Recipient: abuse@dynadot.com Victim safety and official reportingImmediate actions and verified reporting channels
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.