ulvionen.digital
“Vignette Österreich – Informationen zu Preisen und Kauf”
Security analysis of ulvionen.digital covers observed phishing indicators, infrastructure evidence, current status, and defensive guidance.
The detailed PhishDestroy AI analysis below remains in English to preserve the original forensic record.
Evidence Summary
The domain ulvionen.digital was registered on February 22, 2026 through Dynadot LLC and is currently resolved to the IP address 172.67.175.130, which belongs to AS13335 Cloudflare, Inc. and is geolocated in the United States. DNS resolution uses the Cloudflare authoritative nameservers hugh.ns.cloudflare.com and blakely.ns.cloudflare.com. An HTTPS request to the host returns HTTP status code 200 and presents a TLS certificate issued by Google Trust Services under the WE1 profile, indicating a valid, publicly trusted certificate chain. The page title observed for the site is "Vignette Österreich – Informationen zu Preisen und Kauf," a German‑language phrase that does not directly reveal a targeted brand or service. Technical fingerprinting shows the presence of Cloudflare Browser Insights, standard Cloudflare services, and HTTP/3 support.
From a threat intelligence perspective the domain is classified as a high‑risk generic phishing site and is marked as active. It appears on one external security blocklist and has been explicitly blocked by the PhishDestroy service. VirusTotal analysis reports that one out of ninety‑five scanning engines flagged the domain, while the Gridinsoft trust score is recorded as 0 / 100, reinforcing the suspicion of malicious intent. No additional detection vendors, Safe Browsing listings, or Open Threat Exchange (OTX) references are provided.
Given the limited public content, the exact phishing narrative and any credential‑harvesting mechanisms remain unknown. However, the combination of a newly registered domain, Cloudflare‑hosted infrastructure, a valid SSL certificate, and an observed page title that could be leveraged to lure German‑speaking users suggests a purposeful attempt to deceive victims. Defenders should prioritize blocking the domain and its associated IP address at perimeter firewalls and DNS filtering layers.
Network Security Intelligence
Forensic History & Detection Timeline
-
VirusTotal Detections Update Mar 1, 2026 · 05:07 UTCVirusTotal scanner detections updated from 1 to 2. Added scanner alerts: SOCRadar.
-
Cloudflare Radar Scan Feb 27, 2026 · 05:00 UTCCloudflare Radar scan registered: View Radar report.
Threat Response Pipeline
Public Blocklist Status
Stored observation
Observed title contrast
Stored Capture · 2 sources
Domain Intelligence
Technical detailsDNS, SSL SANs, timestamps
ICANN OVERSIGHT
Accreditation and RAA context
Accreditation and RAA context
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Technologies · 3 identified
VirusTotal Analysis
Archived Evidence
Site Performance Analysis
Google PageSpeed Insights — mobile performance audit of ulvionen.digital · checked Mar 2, 2026
Community reports
Reported by 1 community member, first seen Feb 22, 2026
- Stored reports
- 1
- Unique reported URLs
- 1
Evidence & External Reports
Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive