cx718554-wordpress-f7iuo[.]tw1[.]ru
“Домен припаркован в Timeweb”
cx718554-wordpress-f7iuo.tw1.ru — Nicht bestätigt. Markenidentität: Wordpress; Betrugstyp: Brand Impersonation. Zusammenfassung der Beweislage: VirusTotal 11/91 (ADMINUSLabs, alphaMountain.ai, BitDefender, ESET, Fortinet); CF Radar malicious; PhishDestroy score 88/100. Registrar: TW-Cloud (ASN: 9123).
Die ausführliche Analyse von PhishDestroy AI bleibt auf Englisch, damit der ursprüngliche forensische Bericht unverändert bleibt.
The domain cx718554-wordpress-f7iuo.tw1.ru is confirmed to pose a specific threat of brand impersonation, targeting WordPress users. Analysis indicates that the domain was used to mislead users into believing it is an official WordPress site, potentially to harvest login credentials or other sensitive information. The domain is currently offline, but the risk remains elevated due to its previous activities and the number of security vendors that flagged it.
Infrastructure analysis reveals that this domain was registered through TW-Cloud (ASN: 9123) and resolves to the IP address 92.53.96.105, located in Russia (RU) under the Autonomous System AS9123 JSC TIMEWEB. On VirusTotal, 12 out of 95 security vendors flagged this domain as malicious, indicating a significant level of suspicion among security experts. Additionally, the domain appears on 2 security blocklists: PhishDestroy and PhishingDB. The page title found when the domain was active was 'Домен припаркован в Timeweb', which translates to 'Domain parked at Timeweb', suggesting that the domain was parked or not actively being used for legitimate purposes during the analysis.
If users have visited this domain, they should immediately check their WordPress accounts for any unauthorized activity. It is recommended to change passwords and enable two-factor authentication (2FA) if it is not already activated. Users should also monitor their accounts for any unusual transactions or changes and report any suspicious activity to their hosting provider or WordPress support. Security professionals are advised to block this domain and similar IP addresses to prevent further potential compromises.
Sicherheitssignale
Erkenntnisse zur Netzwerksicherheit
Pipeline zur Reaktion auf Sicherheitsbedrohungen
Status der öffentlichen Sperrliste
VirusTotal-Analyse
Archivierte Beweise
Nachweise und externe Berichte
Wurden Sie von dieser Website betroffen?
Wenn Sie Kontoanmeldeinformationen, persönliche oder Zahlungsinformationen eingegeben oder eine Datei von dieser Domain heruntergeladen haben, ergreifen Sie sofort Maßnahmen. Nachfolgend finden Sie Ressourcen, die Ihnen helfen, den Vorfall zu melden und sich zu schützen.
Melden Sie sich bei Ihren örtlichen Behörden
Wählen Sie Ihr Land aus, um Offizielle Kontakte im Bereich Cyberkriminalität oder einen Beschwerdeentwurf erstellen → zu erhalten.
Jede beliebige Domain prüfen
Bedrohungsanalyse anhand gespeicherter Blocklisten, WHOIS, DNS und öffentlicher Scan-Beweise
Jetzt scannenPhishing melden
Melden Sie verdächtige Domains an unsere Bedrohungsdatenbank – schützen Sie die Community
MeldenEchtzeit-Bedrohungsfeed
Aktuelle Phishing-Meldungen und beobachtete Verfügbarkeitsänderungen
ÜberwachenBleiben Sie auf dem Laufenden, bleiben Sie sicher
Beobachten Sie aktuelle Bedrohungen oder legen Sie Widerspruch gegen diesen Eintrag ein, wenn Sie der Meinung sind, dass es sich um einen Fehlalarm handelt