Notification and current-status evidence
The sent-report ledger records the first outgoing report at . A report was sent to the recorded registrar; contact details remain in Domain Intelligence. The latest stored availability evidence still shows the domain reachable; 6 months has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
selfcare-caa[.]wirk[.]io
“Crédit Agricole Assurances - Selfcare Wirk KYC”
Zusammenfassung der Beweislage
This domain, selfcare-caa.wirk.io, is identified as a credential harvesting phishing site targeting customers of Crédit Agricole Assurances. The page title, 'Crédit Agricole Assurances - Selfcare Wirk KYC,' mimics legitimate self-service portals to deceive users into submitting sensitive authentication credentials, including multi-factor authentication tokens and personal identification documents. Analysis indicates the site employs social engineering tactics to exploit trust in financial institutions, particularly during know-your-customer (KYC) verification processes. Infrastructure analysis reveals the domain was registered through OVH SAS on February 21, 2026, an anomalous future-dated registration suggesting potential domain spoofing or registrar manipulation. The site resolves to IP address 172.67.72.44 and is served via Cloudflare, leveraging HTTP/3 and HSTS to enhance perceived legitimacy. Detection metrics show 2 out of 95 security engines on VirusTotal flag the domain as malicious, while it appears on one security blocklist. The SSL certificate is issued by Google Trust Services, and the site utilizes Microsoft ASP.NET, jQuery, and Cloudflare Browser Insights, further obscuring its true nature. Users who accessed selfcare-caa.wirk.io should immediately revoke any submitted credentials and monitor associated financial accounts for unauthorized activity. It is recommended to reset passwords using a trusted device and enable additional authentication layers, such as hardware tokens or biometric verification. Organizations should update internal blocklists to include the domain and IP 172.67.72.44, and report the incident to relevant cybersecurity authorities for further investigation. The domain has since been taken offline, but similar campaigns may emerge using comparable infrastructure.
Momentaufnahme der übermittelten Beweise
- Gesendet
- Protokolleinträge
- 1
- Fall-ID
PD-20260125-DBCADF- PDF-Artefakt
- PDF-Beweis
Rechtsgrundlage
Vollständiger Beweistext
Acceptable Use Policy (AUP): The domain selfcare-caa.wirk.io is engaged in phishing activities, which constitutes a clear violation of your AUP prohibiting illegal activities, fraud, and deception.
Terms of Service (TOS): The ongoing use of this domain for phishing purposes violates your TOS, which reserves the right to suspend or terminate services for any activities that are illegal or harmful.
Applicable Laws (Unknown):
Computer Fraud and Abuse Act (CFAA): This U.S. federal law prohibits unauthorized access to computers and networks, which is applicable to phishing schemes that deceive users into providing sensitive information.
Wire Fraud Statute (18 U.S.C. § 1343): This law criminalizes schemes to defraud individuals or entities through electronic communications, including phishing attacks that exploit trust.
CAN-SPAM Act (15 U.S.C. § 7701): This act regulates commercial email and prohibits deceptive practices, which are inherent in phishing attempts.
Regulatory Note: Failure to take immediate action against this domain may result in liability for facilitating illegal activities and could expose your organization to regulatory scrutiny and potential penalties.
Data Coverage
Erkenntnisse zur Netzwerksicherheit
Pipeline zur Reaktion auf Sicherheitsbedrohungen
Blocklistenabdeckung
10 überwachte externe Feeds · gespeicherter Stand 12.08.2026
Erkennungszeitleiste
-
Cloudflare Radar
Cloudflare-Radar-Scan gespeichert · Scan öffnen
VirusTotal-Analyse
Website-Performanceanalyse
Google PageSpeed Insights — mobile performance audit of selfcare-caa.wirk.io · checked Jun 27, 2026
Wurden Sie von dieser Website betroffen?
Wenn Sie Kontoanmeldeinformationen, persönliche oder Zahlungsinformationen eingegeben oder eine Datei von dieser Domain heruntergeladen haben, ergreifen Sie sofort Maßnahmen. Nachfolgend finden Sie Ressourcen, die Ihnen helfen, den Vorfall zu melden und sich zu schützen.
Melden Sie sich bei Ihren örtlichen Behörden
Wählen Sie Ihr Land aus, um Offizielle Kontakte im Bereich Cyberkriminalität oder einen Beschwerdeentwurf erstellen → zu erhalten.
Jede beliebige Domain prüfen
Bedrohungsanalyse anhand gespeicherter Blocklisten, WHOIS, DNS und öffentlicher Scan-Beweise
Jetzt scannenPhishing melden
Melden Sie verdächtige Domains an unsere Bedrohungsdatenbank – schützen Sie die Community
MeldenEchtzeit-Bedrohungsfeed
Aktuelle Phishing-Meldungen und beobachtete Verfügbarkeitsänderungen
ÜberwachenBleiben Sie auf dem Laufenden, bleiben Sie sicher
Beobachten Sie aktuelle Bedrohungen oder legen Sie Widerspruch gegen diesen Eintrag ein, wenn Sie der Meinung sind, dass es sich um einen Fehlalarm handelt