it-collab[.]land
Phishing- und Sicherheitsprüfung für it-collab.land
it-collab.land — Letzter bekanntermaßen aktiv (HTTP 200). Zusammenfassung der Beweislage: VirusTotal 8/91 (alphaMountain.ai, CRDF, CyRadar, Fortinet, G-Data); Spamhaus DBL_PHISH; PhishDestroy score 84/100. Registrar: NiceNIC.
Die ausführliche Analyse von PhishDestroy AI bleibt auf Englisch, damit der ursprüngliche forensische Bericht unverändert bleibt.
Evidence Analysis
Analysis as of July 19 2026 indicates that the domain it-collab.land is currently operating a generic phishing campaign. The website returns HTTP status 200 and is protected by a TLS certificate issued by Google Trust Services using the WE1 intermediate, confirming a valid HTTPS endpoint. DNS resolution points to the Cloudflare IP address 188.114.97.3, which is geolocated to Canada, and the domain is delegated to the Cloudflare nameservers bjorn.ns.cloudflare.com and laylah.ns.cloudflare.com. Registration was performed through NICENIC INTERNATIONAL GROUP CO., LIMITED. The domain appears on one public blocklist, has been cited in two AlienVault OTX threat pulses, and is blocked by PhishDestroy. VirusTotal scans show eight of ninety‑one security vendors flagging the domain. No additional details about the landing page, payload, or targeted brand have been disclosed. Defenders should add the domain to DNS and URL filtering blocks, monitor network flows for connections to the associated Cloudflare IP, and incorporate the indicator into SIEM correlation rules to detect attempted credential harvesting. Continuous monitoring is recommended to capture any changes in hosting or content.
Datenabdeckung12 recorded checks
Erkenntnisse zur Netzwerksicherheit Registrar context
Pipeline zur Reaktion auf Sicherheitsbedrohungen
Status der öffentlichen Sperrliste
Domain-Intelligenz
Technische DetailsDNS, SSL-SANs, Zeitstempel
ICANN OVERSIGHT
Akkreditierung und RAA-Kontext
Akkreditierung und RAA-Kontext
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Latest Classified Outcome 2026-08-09 02:54:15 UTC
Technologien · 3 identified
HTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org 100 % KonfidenzHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100 % KonfidenzVirusTotal-Analyse
Website-Performanceanalyse
Google PageSpeed Insights — mobile performance audit of it-collab.land · checked Jul 20, 2026
Nachweise und externe BerichteIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
Wenn Sie Kontoanmeldeinformationen, persönliche oder Zahlungsinformationen eingegeben oder eine Datei von dieser Domain heruntergeladen haben, ergreifen Sie sofort Maßnahmen. Nachfolgend finden Sie Ressourcen, die Ihnen helfen, den Vorfall zu melden und sich zu schützen.
Melden Sie sich bei Ihren örtlichen Behörden
Wählen Sie Ihr Land aus, um Offizielle Kontakte im Bereich Cyberkriminalität oder einen Beschwerdeentwurf erstellen → zu erhalten.