creteportway[.]live
“Crête Portway | Official Platform for AI Assisted Trading”
Zusammenfassung der Beweislage
The domain creteportway.live was registered on May 15, 2026 through NICENIC INTERNATIONAL GROUP CO., LIMITED and currently resolves to the Cloudflare address 172.67.212.81 located in Canada. An HTTPS service is presented using a Let's Encrypt certificate (E8) and the web server returns HTTP status 200. The page title presented to visitors reads 'Crête Portway | Official Platform for AI Assisted Trading', suggesting an attempt to masquerade as a legitimate financial service. Infrastructure analysis shows the domain is served entirely from Cloudflare's network, as indicated by the authoritative nameservers adi.ns.cloudflare.com and leland.ns.cloudflare.com. The Cloudflare edge location masks the true origin server, a common tactic for phishing infrastructure to evade takedown and to benefit from Cloudflare's built‑in DDoS protection. The SSL certificate is valid and automatically renewed, which further reduces visual cues of malicious intent. Threat intelligence corroborates malicious intent: the domain appears on a single security blocklist and has been listed by PhishDestroy as a phishing site. VirusTotal scans have flagged the domain in 3 out of 95 security vendors, and Gridinsoft assigns a trust score of 0 out of 100, indicating extreme suspicion. AlienVault OTX references the domain in one threat pulse, and the same indicator was observed in a recent campaign targeting users of AI‑assisted trading platforms. Defenders should treat creteportway.live as a high‑risk phishing vector. Immediate network‑level blocking of the domain and its associated IP address is advised, along with monitoring of outbound DNS queries for the listed nameservers. Because the underlying hosting is abstracted behind Cloudflare, takedown attempts may require coordination with the registrar. Continuous observation is needed to detect any content changes that could expand the phishing campaign.
Data Coverage
Erkenntnisse zur Netzwerksicherheit
Pipeline zur Reaktion auf Sicherheitsbedrohungen
Blocklistenabdeckung
10 überwachte externe Feeds · gespeicherter Stand 12.08.2026
Gespeicherte Ergebnisnachweise
Ergebnis und Takedown-Zuordnung
- Ergebnis
live_content- Verfügbarkeit
content_live- Ursache
content_served- Konfidenz
- 90%
- Erste Beobachtung
- Letzte Beobachtung
Beweis-SHA-256 acb9eaba2d4a
Erkennungszeitleiste
-
Domainstatus
Erreichbar → Nicht erreichbar
-
Domainstatus
Nicht erreichbar → Erreichbar
-
Verfügbarkeit
Erster gespeicherter Wert: Unbekannt
993d00c35140 -
Verfügbarkeit
Unbekannt → Aktive Inhalte
7eefe8b36ff6 -
Verfügbarkeit
Aktive Inhalte → Unbekannt
83374d9d652c -
Verfügbarkeit
Unbekannt → Aktive Inhalte
ed9bab14625c -
Verfügbarkeit
Aktive Inhalte → Unbekannt
3b1d50e297ea -
Verfügbarkeit
Unbekannt → Aktive Inhalte
8563e2ab3816 -
Verfügbarkeit
Aktive Inhalte → Unbekannt
ca255b61650a -
Verfügbarkeit
Unbekannt → Aktive Inhalte
b6662122d035
Alle anzeigen (6)
-
Verfügbarkeit
Aktive Inhalte → Unbekannt
d8f7d37d7f95 -
Verfügbarkeit
Unbekannt → Aktive Inhalte
b5ba436ee604 -
Verfügbarkeit
Aktive Inhalte → Unbekannt
afa49a2b04dd -
Verfügbarkeit
Unbekannt → Aktive Inhalte
faf42d7668c5 -
Verfügbarkeit
Aktive Inhalte → Unbekannt
e70d6b0bd31a -
Verfügbarkeit
Unbekannt → Aktive Inhalte
acb9eaba2d4a
Community-Meldungen
Von 1 Community-Mitglied gemeldet; erstmals gesehen am 15.05.2026
- Gespeicherte Meldungen
- 1
- Eindeutige gemeldete URLs
- 1
Domain-Intelligenz
Technische DetailsDNS, TLS-Namen und Zeitstempel
ICANN OVERSIGHT
Akkreditierung und RAA-Kontext
Akkreditierung und RAA-Kontext
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
VirusTotal-Analyse
Analyse der Website-Konfiguration
Wurden Sie von dieser Website betroffen?
Wenn Sie Kontoanmeldeinformationen, persönliche oder Zahlungsinformationen eingegeben oder eine Datei von dieser Domain heruntergeladen haben, ergreifen Sie sofort Maßnahmen. Nachfolgend finden Sie Ressourcen, die Ihnen helfen, den Vorfall zu melden und sich zu schützen.
Melden Sie sich bei Ihren örtlichen Behörden
Wählen Sie Ihr Land aus, um Offizielle Kontakte im Bereich Cyberkriminalität oder einen Beschwerdeentwurf erstellen → zu erhalten.
Jede beliebige Domain prüfen
Bedrohungsanalyse anhand gespeicherter Blocklisten, WHOIS, DNS und öffentlicher Scan-Beweise
Jetzt scannenPhishing melden
Melden Sie verdächtige Domains an unsere Bedrohungsdatenbank – schützen Sie die Community
MeldenEchtzeit-Bedrohungsfeed
Aktuelle Phishing-Meldungen und beobachtete Verfügbarkeitsänderungen
ÜberwachenBleiben Sie auf dem Laufenden, bleiben Sie sicher
Beobachten Sie aktuelle Bedrohungen oder legen Sie Widerspruch gegen diesen Eintrag ein, wenn Sie der Meinung sind, dass es sich um einen Fehlalarm handelt