post[.]ch-zahlungssystem[.]sale
post.ch-zahlungssystem.sale — Inhalt nicht verfügbar (HTTP 502). Zusammenfassung der Beweislage: VirusTotal 15/93 (ADMINUSLabs, Criminal IP, BitDefender, CRDF, CyRadar); Spamhaus DBL_PHISH; PhishDestroy score 95/100.
Die ausführliche Analyse von PhishDestroy AI bleibt auf Englisch, damit der ursprüngliche forensische Bericht unverändert bleibt.
The domain post.ch-zahlungssystem.sale was registered on February 21, 2026 and currently resolves to the IPv4 address 172.67.174.247, which is owned by Cloudflare, Inc. (AS13335) and geolocated to the United States. The domain’s SSL certificate is identified as WE1, indicating a valid TLS layer but offering no additional trust signals. VirusTotal has recorded 15 positive detections out of 93 scanned security vendors, confirming that multiple independent scanners flag the domain as malicious. It appears on a single public blocklist and is actively blocked by the PhishDestroy service, reinforcing the consensus that the domain is being used for phishing.
The threat classification supplied is “generic phishing,” and the risk level is elevated. The site has been taken offline, as indicated by the status flag, and no HTTP response body or page title is available for further analysis. Defenders should add the IP address 172.67.174.247 to network‑level deny lists only after confirming that legitimate services are not hosted on the same address, recognizing that Cloudflare’s shared infrastructure may host unrelated traffic. The domain name itself should be added to URL filtering and email security policies to block any future attempts to reference it.
Continuous monitoring of the associated IP and ASN for new malicious domains is advised, as threat actors frequently reuse Cloudflare edge nodes. Because the domain is already flagged by VirusTotal and PhishDestroy, automated blocklist feeds will likely capture future re‑registrations, but manual rule updates provide an additional safety net. Until further forensic evidence, such as page content or credential harvesting behavior, becomes available, the recommendation is to treat post.ch‑zahlungssystem.sale as a high‑confidence phishing indicator and enforce strict deny controls across perimeter defenses.
Pipeline zur Reaktion auf Sicherheitsbedrohungen
Status der öffentlichen Sperrliste
Forensische Erkenntnisse
VirusTotal-Analyse
Nachweise und externe Berichte
Wurden Sie von dieser Website betroffen?
Wenn Sie Kontoanmeldeinformationen, persönliche oder Zahlungsinformationen eingegeben oder eine Datei von dieser Domain heruntergeladen haben, ergreifen Sie sofort Maßnahmen. Nachfolgend finden Sie Ressourcen, die Ihnen helfen, den Vorfall zu melden und sich zu schützen.
Melden Sie sich bei Ihren örtlichen Behörden
Wählen Sie Ihr Land aus, um Offizielle Kontakte im Bereich Cyberkriminalität oder einen Beschwerdeentwurf erstellen → zu erhalten.
Jede beliebige Domain prüfen
Bedrohungsanalyse anhand gespeicherter Blocklisten, WHOIS, DNS und öffentlicher Scan-Beweise
Jetzt scannenPhishing melden
Melden Sie verdächtige Domains an unsere Bedrohungsdatenbank – schützen Sie die Community
MeldenEchtzeit-Bedrohungsfeed
Aktuelle Phishing-Meldungen und beobachtete Verfügbarkeitsänderungen
ÜberwachenBleiben Sie auf dem Laufenden, bleiben Sie sicher
Beobachten Sie aktuelle Bedrohungen oder legen Sie Widerspruch gegen diesen Eintrag ein, wenn Sie der Meinung sind, dass es sich um einen Fehlalarm handelt