MALICIOUS — CRITICAL
cici606[.]net
The domain cici606.net was registered on 08 December 2025 through NameSilo, LLC and is currently resolved to the IPv4 address 151.241.30.74.
- VirusTotal
- 5/91
- Blocklists
- No stored match
- Availability
- Content unavailable · HTTP 502
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
Evidence Analysis
Is cici606.net a phishing scam?
The domain cici606.net was registered on 08 December 2025 through NameSilo, LLC and is currently resolved to the IPv4 address 151.241.30.74.
The domain cici606.net was registered on 08 December 2025 through NameSilo, LLC and is currently resolved to the IPv4 address 151.241.30.74. The domain remains active as of the report date 06 August 2026 and is listed on one external security blocklist. Reputation data from VirusTotal shows that five out of ninety‑one scanning engines have flagged the domain, indicating a non‑trivial detection rate for malicious activity. The domain is also explicitly blocked by the PhishDestroy service, reinforcing the assessment of phishing risk.
Nameserver configuration includes ns1.cici606.net, ns2.cici606.net and two ancillary records ns1.ultahooosttts.icu and ns2.ultahooosttts.icu, suggesting a split‑hosting set‑up that may be used to increase resilience or evade takedown efforts. The available evidence points to a generic phishing campaign, but the specific target or lure employed by cici606.net has not been observed in the current intelligence set. Consequently, the precise payload or credential‑ harvesting method remains uncertain. Defenders should add 151.241.30.74 to network‑level deny lists and enforce DNS filtering for cici606.net on endpoint and gateway solutions.
Monitoring for additional hostnames that resolve to the same IP, as well as any new entries on blocklists that reference the domain, will help to capture potential expansion of the infrastructure. Because the registrar is NameSilo, investigators may consider requesting registration details from the registrar if further attribution is required. In summary, the combination of recent creation, active resolution, multiple vendor detections, and inclusion on a dedicated phishing blocklist makes cici606.net a high‑risk indicator that should be blocked and continuously monitored.
Stored source results
Recorded verdicts and infrastructure observations for this domain.
Data coverage12 recorded checks
Network Security Intelligence Registrar context
Threat Response Pipeline
Public Blocklist Status
Stored Capture
Domain Intelligence
Technical detailsDNS, SSL SANs, timestamps
ICANN OVERSIGHT
Accreditation and RAA context
Accreditation and RAA context
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Technologies · 6 identified
WordPress is a free and open-source content management system written in PHP and paired with a MySQL or MariaDB database. Features include a plugin architecture and a template system.
wordpress.org 100% confidenceAMP, originally created by Google, is an open-source HTML framework developed by the AMP open-source Project. AMP is designed to help webpages load faster.
www.amp.dev 100% confidenceHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100% confidenceVirusTotal Analysis
Archived Evidence
Site Performance Analysis
Google PageSpeed Insights — mobile performance audit of cici606.net · checked Aug 6, 2026
Evidence & External ReportsIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.