capybobo[.]network
“Nur einen Moment…”
The domain capybobo.network is currently flagged as a high‑risk generic phishing site. Active status is confirmed as of 12 July 2026, and the domain appears on the PhishDestroy blocklist. Its risk rating is elevated due to the presence of multiple malicious indicators and a zero trust score from a reputable reputation engine. Infrastructure analysis shows the site is served through Cloudflare’s network, resolving to IP address 172.67.179.116 owned by AS13335. The SSL certificate is issued by Google Trust Services under the WE1 profile, indicating a valid TLS layer despite the malicious intent. Both nameservers, meilani.ns.cloudflare.com and zahir.ns.cloudflare.com, are Cloudflare‑managed, and the site employs Cloudflare Browser Insights and HTTP/3 support. Dynamic content inspection is limited; the only retrieved page element is the title “Nur einen Moment…”, which translates to “Just a moment…”. The HTTP response returns a 403 status code, suggesting access restrictions that may be used to evade automated analysis. VirusTotal reports that 2 out of 95 security vendors have flagged the domain, reinforcing the suspicion. No additional intelligence such as targeted brand or payload details is available, leaving the exact phishing workflow uncertain. Defenders should immediately block traffic to capybobo.network at perimeter and DNS filtering layers. Continuous monitoring of outbound connections to the associated Cloudflare IP range is advised, as the infrastructure could be leveraged for credential harvesting or redirect campaigns. Since the site is already listed on a security blocklist, adding it to internal blocklists will reduce exposure. Periodic re‑scanning is recommended to capture any changes in content or hosting configuration.
Threat Response Pipeline
Public Blocklist Status
Stored Capture
Domain Intelligence
Technical detailsDNS, SSL SANs, timestamps
ICANN OVERSIGHT
Accreditation and RAA context
Accreditation and RAA context
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Technologies · 3 identified
Performance monitoring tool that measures website speed from real users.
www.cloudflare.comWeb infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
VirusTotal Analysis
Archived Evidence
Evidence & External Reports
Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive