Zum Sicherheitsbericht springen
⚠️
Diese Domain wurde als bösartig markiert.
Sicherheits-Engines melden eine Entdeckung: 15. Seien Sie äußerst vorsichtig – Geben Sie keine Anmeldeinformationen oder persönlichen Daten ein.
ABUSE NOTICE · 7D+ OPEN Outgoing abuse reports are recorded; the latest stored availability evidence still shows the domain reachable.
Notification and current-status evidence

The sent-report ledger records the first outgoing report at . A report was sent to the recorded registrar; contact details remain in Domain Intelligence. The latest stored availability evidence still shows the domain reachable; 6 months has elapsed since the first outgoing report.

ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.

Elapsed since first report
6 months
Reports sent
1
Current status
HTTP 302 at latest stored check
Domänensicherheit und Bedrohungsinformationen

emktlw[.]com[.]br

“Autenticação Locaweb”

Drohungsurteil Kritisch 100/100 Evidenzbewertung
Verfügbarkeit Letzter bekanntermaßen aktiv Letzte gespeicherte Erreichbarkeitsbeobachtung
VirusTotal-Erkennungen: 15/91 URLQuery threat systems: 3 alerts Letzter bekanntermaßen aktiv
OTX: 16 refs 04.02.2026 1 Report Sent

Zusammenfassung der Beweislage

KRITISCH
Evidence score
100/100

The domain emktlw.com.br was registered on February 21, 2026 through the LOCAWEB registrar and is presently active. DNS resolution points to the IP address 186.202.135.197, which belongs to AS27715 Locaweb Serviços de Internet S/A located in Brazil. The host presents a GlobalSign nv-sa / GlobalSign GCC R6 AlphaSSL CA 2025 certificate, indicating a valid TLS chain, and the HTTP response is a 302 redirect, a behavior often used to forward victims to credential‑harvesting pages. The page title returned by the server is "Autenticação Locaweb," suggesting the site is attempting to impersonate a legitimate Locaweb authentication portal.

Security‑reputation services uniformly score the domain very poorly; Gridinsoft assigns a trust rating of 1 out of 100, Scamadviser records the same score, and the domain appears on at least one public blocklist, specifically PhishDestroy. VirusTotal analysis shows that 12 of 93 scanning engines flag the domain as malicious, reinforcing the suspicion of abuse. AlienVault OTX lists the domain in sixteen distinct threat‑intel pulses, indicating repeated observations across multiple feeds. Technical fingerprints include the deployment of reCAPTCHA, HTTP Strict Transport Security (HSTS), and Google Analytics, which are commonly observed on both legitimate and fraudulent sites but do not mitigate the underlying phishing intent.

The site is associated with the "Recovery Scam" phishing kit, a known template used to solicit credentials under the pretext of account recovery. While the exact content of the landing page has not been disclosed, the combination of a legitimate‑looking title, active redirect, low trust scores, and multiple vendor detections provides strong evidence of a high‑risk phishing operation. Defenders should block the domain at the network perimeter, add the associated IP address to deny lists, and monitor for any traffic that includes the observed user‑agent strings or analytics identifiers.

Momentaufnahme der übermittelten Beweise

Gesendet
Protokolleinträge
1
Fall-ID
PD-20260204-0C6B55
Titel der erfassten Seite
Autenticação Locaweb
PDF-Artefakt
PDF-Beweis
Vollständiger Beweistext
Policy Violations:
Acceptable Use Policy (AUP): The domain emktlw.com.br is engaged in phishing activities, which constitutes a direct violation of your AUP prohibiting illegal activities, fraud, and deception.
Terms of Service (TOS): The continued operation of this domain violates your TOS, which reserves the right to suspend or terminate services for any activities that contravene legal statutes or promote fraudulent behavior.
Applicable Laws (BR):
Lei nº 12.737/2012 (Carolina Dieckmann Law): This law criminalizes unauthorized access to computer systems and data, which is relevant as phishing involves deceitful access to sensitive information.
Lei nº 13.709/2018 (General Data Protection Law - LGPD): Phishing activities violate the principles of data protection and privacy established under this law, particularly regarding the unauthorized processing of personal data.
Regulatory Note: Non-compliance with your AUP and TOS, as well as applicable Brazilian laws, may result in legal repercussions and regulatory scrutiny. Immediate action is required to mitigate potential liability.
VirusTotal
VirusTotal
15 det.
URLQuery
URLQuery
3 threat alerts
OTX references
TLS-Zertifikat
GlobalSign GCC R6 AlphaSSL CA 2025
Beobachteter Status
Letzter bekanntermaßen aktiv HTTP 302
PhishDestroy
DestroyList
Gelistet
Reports Sent
1

Data Coverage

VirusTotal 15 / 91 URLQuery 3 threat-system alerts PhishStats nicht geprüft OTX 16 community references CF-Radar scan completed URLScan capture gespeicherter Bericht URLScan verdict Analyse abgeschlossen DNS-Sperren 14 geprüft — keine Sperren TLS valid certificate, 218d WHOIS not parsed Screenshot 3 captures · 3 sources Weiterleitungskette nicht untersucht
Sicherheitssignale
SA Scamadviser Warnings
This website does not have many visitors iQ Abuse Scan tagged this website for phishing DNSFilter reported this website as malicious in the last 30 days IPQS flagged this website for Phishing IPQS has flagged this website as suspicious
According to the SSL check the certificate is valid The owner of the site has claimed the domain name for a long time
GS Gridinsoft Analysis
Hosting SSL Certificate Bootstrap Framework Google Tag Manager Blacklisted by Security Providers Long Term SSL Certificate Heuristic - Scam Established Domain
Erkenntnisse zur Netzwerksicherheit
Threat Detection Systems 3 alerts
Detection System Indicator Verdict Alert
OpenDNS emktlw.com.br phishing Phishing Block
Hagezi Threat Feed emktlw.com.br malicious Sinkholed
DNS4EU emktlw.com.br malicious Sinkholed

Pipeline zur Reaktion auf Sicherheitsbedrohungen

Entdeckung
Checks
Reports
Verfügbarkeit
12/13

Blocklistenabdeckung

10 überwachte externe Feeds · gespeicherter Stand 11.08.2026

10 überwachte externe Feeds Kein Treffer

Erkennungszeitleiste

  1. VirusTotal

    12 → 11

  2. VirusTotal

    12 → 11

Gespeicherte Aufnahme

Domain-Intelligenz

Domain
URLScan Verdict Analyse abgeschlossen score 0 report ↗
Server / ASN Apereo CAS · AS27715 Locaweb Serviços de Internet S/A
IP-Reputation IP abuse confidence 0/100 0 reports checked 16.07.2026
Registrar LOCAWEB BR(BR)
IP-Adresse 186.202.135.197 BR
StandortBR São Paulo, BR
NetzwerkAS27715 · Locaweb Serviços de Internet S/A
RegistrierungExpires 17.07.2027
HTTP-Status302 Found (Temporary)
Elapsed Since First Report 39 days
Was wir zählen Raw elapsed time since the first stored abuse report. It is not a registrar response-time measurement. Latest observed status: Letzter bekanntermaßen aktiv.
Was jeder Bericht enthält Gespeicherte Ausgangsberichtsaufzeichnungen können auf zu diesem Zeitpunkt verfügbare Beweise verweisen, wie z. B. Urteile von Anbietern, Registrierungsdaten, Hosting-Details, Klassifizierungen oder Screenshots. Diese Seite lässt keine Rückschlüsse auf die genaue zugestellte Nutzlast, den Empfang, die Bestätigung oder die Aktion eines Empfängers zu.
Technische DetailsDNS, TLS-Namen und Zeitstempel
Erstmals entdeckt04.02.2026
DOM Analysisanalyzed 09.07.2026DOM analysis score 98/100
Submitted URLhttp://emktlw.com.br/
Nameserverns3.locaweb.com.br
TLS-Beobachtunggültig seit 02.09.2025geprüft am 15.03.2026
Favicon Hash
Seitentitel
Autenticação Locaweb
TLS-Zertifikat
Valid transport encryption · Ausgestellt von GlobalSign GCC R6 AlphaSSL CA 2025 · valid for 218 days
Diese Domain melden Reichen Sie Beweismaterial ein und helfen Sie mit, andere zu schützen

VirusTotal-Analyse

15 / 91 Sicherheitsanbieter haben diese Domain markiert
View on VT
Last analyzed Previous stored snapshot: 12 detections
ADMINUSLabs
Criminal IP
alphaMountain.ai
Certego
Chong Lua Dao
CyRadar
Emsisoft
Forcepoint ThreatSeeker
Fortinet
Gridinsoft
Lionic
SOCRadar
VIPRE
Webroot
desenmascara.me
Website-Performanceanalyse

Google PageSpeed Insights — mobile performance audit of emktlw.com.br · checked Mar 2, 2026

57
Needs Work
Performance
FCP
4.45s
First Contentful Paint
LCP
4.45s
Largest Contentful Paint
CLS
0.02
Cumulative Layout Shift
TBT
360ms
Total Blocking Time
SI
13.95s
Speed Index
Powered by Google PageSpeed Insights · Mobile strategy · Scores: 90-100 Good 50-89 Needs Work 0-49 Poor
Analyse der Website-Konfiguration
Stored observations are retained with their original collection time.
robots.txt Present · HTTP 200
/users/sign_in

Wurden Sie von dieser Website betroffen?

If credentials were compromised, report immediately. Do not engage with recovery scammers.

Wenn Sie Kontoanmeldeinformationen, persönliche oder Zahlungsinformationen eingegeben oder eine Datei von dieser Domain heruntergeladen haben, ergreifen Sie sofort Maßnahmen. Nachfolgend finden Sie Ressourcen, die Ihnen helfen, den Vorfall zu melden und sich zu schützen.

Europol
Finden Sie den offiziellen Meldekanal für Ihr EU-Land
National police directory
Vorsicht vor Betrügern, die mit der Rückforderung von Geldern locken! Kriminelle nehmen unter Umständen erneut Kontakt zu Opfern auf und geben dabei vor, Ermittler, Anwälte oder Beitreibungsbeamte zu sein. Zahlen Sie keine Vorabgebühren und geben Sie keine Anmeldeinformationen weiter. Erfahren Sie mehr über Betrug im Zusammenhang mit Wiederaufbaumaßnahmen →

Melden Sie sich bei Ihren örtlichen Behörden

Wählen Sie Ihr Land aus, um Offizielle Kontakte im Bereich Cyberkriminalität oder einen Beschwerdeentwurf erstellen → zu erhalten.

97-Länder-Verzeichnis
KI-gestützter Entwurf – Vorfalldetails werden vom KI-Anbieter verarbeitet Überprüfen Sie es und reichen Sie es selbst ein

Jede beliebige Domain prüfen

Bedrohungsanalyse anhand gespeicherter Blocklisten, WHOIS, DNS und öffentlicher Scan-Beweise

Jetzt scannen

Phishing melden

Melden Sie verdächtige Domains an unsere Bedrohungsdatenbank – schützen Sie die Community

Melden

Echtzeit-Bedrohungsfeed

Aktuelle Phishing-Meldungen und beobachtete Verfügbarkeitsänderungen

Überwachen

Bleiben Sie auf dem Laufenden, bleiben Sie sicher

Beobachten Sie aktuelle Bedrohungen oder legen Sie Widerspruch gegen diesen Eintrag ein, wenn Sie der Meinung sind, dass es sich um einen Fehlalarm handelt

Echtzeit-Bedrohungsfeed Einspruch gegen diesen Eintrag einlegen

Externe Tools

GridinsoftGridinsoft Vertrauenswert 1/100Status: SuspiciousQuelle öffnen
ScamAdviserScamAdviser Vertrauenswert 1/100Status: Very Likely UnsafeQuelle öffnen
HTML · IFRAME

Diesen Bericht einbetten

Teilen Sie diese Bedrohungsinformationen auf Ihrer Website oder in Ihrem Blog

embed.html
<iframe
  src="https://phishdestroy.io/de/embed/domain/emktlw.com.br"
  title="PhishDestroy threat report for emktlw.com.br"
  width="100%" height="320"
  loading="lazy"
  referrerpolicy="no-referrer"
  sandbox="allow-same-origin allow-popups allow-popups-to-escape-sandbox"
  style="border:0;border-radius:12px;max-width:100%"
></iframe>