zircuitupdates[.]live
فحص التصيد والأمان للنطاق zircuitupdates.live
“Even geduld...”
zircuitupdates.live — المحتوى غير متوفر (HTTP 502). نوع الاحتيال: Credential Phishing. ملخص الأدلة: VirusTotal 2/95 (Fortinet, Gridinsoft); Spamhaus DBL_PHISH; 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 66/100.
يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.
Evidence Analysis
The domain zircuitupdates.live has been identified as a credential phishing threat, specifically designed to impersonate the Zircuit platform. This site attempts to steal login credentials from unsuspecting users by mimicking a legitimate authentication interface. The domain was created on February 21, 2026, and resolves to IP address 172.67.166.111, which is associated with Cloudflare's infrastructure. Security analysis reveals that 2 out of 95 antivirus vendors on VirusTotal flagged this domain as malicious, indicating a moderate but notable detection rate. Additionally, the domain appears on 3 security blocklists, further confirming its malicious intent. Notably, the site lacks an SSL certificate, which is a strong red flag for any legitimate service.
Technical indicators paint a clear picture of the threat. The domain's creation date is recent, suggesting it was set up specifically for this phishing campaign. The IP address 172.67.166.111 is part of Cloudflare's CDN, which can help obscure the true hosting location. Despite this, the absence of HTTPS encryption means any data submitted is transmitted in plain text, making it easy for attackers to intercept credentials. The page title, "Even geduld...", is a Dutch phrase meaning "Please wait...", which may be used to lull victims into a false sense of security while the phishing form loads. Google Safe Browsing likely flags this domain, though specific status is not provided; however, the blocklist presence indicates active monitoring.
Currently, zircuitupdates.live has been taken offline, which is a positive development. However, the risk remains that similar domains may appear or that the same threat actor could launch new campaigns. PhishDestroy recommends that users who may have interacted with this domain change their Zircuit passwords immediately and enable two-factor authentication. Always verify URLs before entering credentials, and rely on official channels to access platforms like Zircuit. The seed for this analysis is 2fe7c3, ensuring unique tracking of this specific threat.
نطاق تغطية البيانات12 recorded checks
مسار الاستجابة للتهديدات Pipeline
حالة قوائم الحظر العامة
التقنيات · 3 identified
Performance monitoring tool that measures website speed from real users.
www.cloudflare.comWeb infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
تحليل VirusTotal
الأدلة المؤرشفة
الأدلة والتقارير الخارجيةIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.