195222666[.]com
Resumen de las pruebas
This domain, 195222666.com, is identified as a credential theft phishing site designed to deceive users into submitting login credentials, financial details, or other sensitive information. The infrastructure mimics legitimate services, tricking victims into entering personal data under false pretenses. Such sites are commonly used in fraudulent campaigns targeting individuals, businesses, or organizations to facilitate account takeovers, identity theft, or unauthorized transactions. Analysis indicates the domain was registered on December 06, 2020, through GoDaddy.com, LLC, and resolves to the IP address 198.18.0.216, located in Hong Kong under AS135581 (ONL-HK). The site is flagged by 18 out of 95 security vendors on VirusTotal, confirming its malicious classification. Additional indicators include a default SSL certificate issued to 'Default Company Ltd,' a common red flag for hastily deployed phishing infrastructure. The domain appears on one security blocklist and was actively blocked by enterprise-level detection systems prior to being taken offline. If you visited 195222666.com or entered any information on the site, immediate action is required. First, cease all interaction with the domain and disconnect the affected device from the network to prevent further data exposure. Change passwords for any accounts accessed or entered on the site, prioritizing email, banking, and social media platforms. Enable multi-factor authentication (MFA) where available to add an additional layer of security. Monitor financial statements and credit reports for unauthorized activity, and report any suspicious transactions to the relevant institution. If the device used to access the site is shared or corporate-owned, notify IT or security teams to conduct a forensic review. Consider scanning the device with updated antivirus software to detect potential malware or backdoors installed during the interaction.
Data Coverage
Señales de seguridad
Inteligencia de seguridad de red
Proceso de respuesta ante amenazas Pipeline
Cobertura de listas de bloqueo
10 fuentes externas supervisadas · instantánea del 11/08/2026
10 fuentes externas supervisadas Sin coincidencias
Cronología de detección
-
Cloudflare Radar
Análisis de Cloudflare Radar almacenado · Abrir análisis
-
VirusTotal
19 → 18
Captura guardada
Inteligencia de dominios
Detalles técnicosDNS, nombres TLS y marcas de tiempo
ICANN OVERSIGHT
Acreditación y contexto RAA
Acreditación y contexto RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Análisis de VirusTotal
¿Te ha afectado esta página web?
Si ingresó credenciales de cuenta, información personal o de pago, o descargó un archivo de este dominio, tome medidas inmediatas. A continuación encontrará recursos que le ayudarán a informar el incidente y protegerse.
Informa a las autoridades locales
Seleccione su país para obtener contactos oficiales de cibercrimen o crear un borrador de queja →.
Comprobar cualquier dominio
Análisis de amenazas utilizando listas de bloqueo almacenadas, WHOIS, DNS y evidencia de escaneo público
Escanear ahoraDenunciar un intento de phishing
Envía los dominios sospechosos a nuestra base de datos de amenazas: protege a la comunidad
DenunciarFlujo de amenazas en tiempo real
Informes de phishing recientes y cambios de disponibilidad observados
MonitorizarMantente informado, mantente a salvo
Supervisa las amenazas en tiempo real o impugna esta entrada si crees que se trata de un falso positivo.