MALICIOUS — CRITICAL
legalfinances[.]live
This domain, legalfinances.live, is currently flagged as an active credential harvesting phishing site targeting financial services users.
- VirusTotal
- 1/91
- Blocklists
- No stored match
- Verfügbarkeit
- Letzter bekanntermaßen aktiv · HTTP 200
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Notification and current-status evidence
The sent-report ledger records the first outgoing report at .
The recorded recipient is abuse@identitydigital.com.
The latest stored availability evidence still shows the domain reachable; 27 days has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
Jump to section
legalfinances.live — Letzter bekanntermaßen aktiv (HTTP 200). Betrugstyp: Credential Phishing. Zusammenfassung der Beweislage: VirusTotal 1/91 (SOCRadar); URLQuery 1 alert; Spamhaus DBL_PHISH; PhishDestroy score 76/100. Registrar: NiceNIC.
Die ausführliche Analyse von PhishDestroy AI bleibt auf Englisch, damit der ursprüngliche forensische Bericht unverändert bleibt.
Evidence Analysis
This domain, legalfinances.live, is currently flagged as an active credential harvesting phishing site targeting financial services users. Analysis indicates the infrastructure is designed to impersonate legitimate financial platforms, though no specific brand impersonation has been confirmed at this stage. The domain remains operational and under investigation for fraudulent activity. Infrastructure analysis reveals the domain was registered through NICENIC INTERNATIONAL GROUP CO., LIMITED on July 07, 2026, with no prior history or reputation. It resolves to the IP address 172.67.181.196, which has not been flagged by any of the 95 vendors on VirusTotal as of the latest scan. No blocklist entries or trust score downgrades have been recorded, suggesting the domain has evaded detection mechanisms despite its recent creation and suspicious purpose. Current status shows the domain remains active and unflagged by security vendors, posing a continued risk to users. Organizations and individuals are advised to implement network-level blocking for 172.67.181.196 and monitor for connections to legalfinances.live. Security teams should treat any interaction with this domain as a potential credential compromise event and initiate password resets for affected accounts. Proactive DNS filtering and endpoint detection rules are recommended to mitigate exposure.
Datenabdeckung12 recorded checks
Erkenntnisse zur Netzwerksicherheit Registrar context
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Hagezi Threat Feed | legalfinances.live |
malicious | Sinkholed |
Pipeline zur Reaktion auf Sicherheitsbedrohungen
Status der öffentlichen Sperrliste
Gespeicherte Aufnahme
Domain-Intelligenz
Technische DetailsDNS, SSL-SANs, Zeitstempel
ICANN OVERSIGHT
Akkreditierung und RAA-Kontext
Akkreditierung und RAA-Kontext
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Latest Classified Outcome 2026-08-09 02:44:21 UTC
Technologien · 3 identified
Cloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com 100 % KonfidenzHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100 % KonfidenzVirusTotal-Analyse
Nachweise und externe BerichteIndependent lookups and source reports
PD-20260713-3FFDCC Recipient: abuse@identitydigital.com Victim safety and official reportingImmediate actions and verified reporting channels
Wenn Sie Kontoanmeldeinformationen, persönliche oder Zahlungsinformationen eingegeben oder eine Datei von dieser Domain heruntergeladen haben, ergreifen Sie sofort Maßnahmen. Nachfolgend finden Sie Ressourcen, die Ihnen helfen, den Vorfall zu melden und sich zu schützen.
Melden Sie sich bei Ihren örtlichen Behörden
Wählen Sie Ihr Land aus, um Offizielle Kontakte im Bereich Cyberkriminalität oder einen Beschwerdeentwurf erstellen → zu erhalten.