1lnch[.]fi-v2[.]to
“1lnch.fi-v2.to”
1lnch.fi-v2.to — Contenido no disponible. Suplantación de marca: Genericcloudflare. Resumen de las pruebas: VirusTotal 16/95 (ADMINUSLabs, BitDefender, Certego, CRDF, CyRadar); URLScan malicious verdict; Spamhaus DBL_PHISH; PhishDestroy score 100/100. Registrador: Government of Kingdom ….
El análisis detallado de PhishDestroy AI se mantiene en inglés para conservar el registro forense original.
Analysis of the domain 1lnch.fi-v2.to, created on 17 November 2025 and currently taken offline, indicates it is part of a generic phishing campaign. The domain resolves to the Cloudflare address 172.67.172.31, belonging to AS13335 in the United States. Nameservers listed are desiree.ns.cloudflare.com and valentin.ns.cloudflare.com, confirming Cloudflare hosting. The registrar is recorded as the Government of Kingdom of Tonga, a pattern often observed in malicious registrations that exploit lax oversight. No TLS certificate is presented, meaning the site operates without HTTPS, reducing transport‑level authentication.
Reputation services assign extremely low trust scores: Scamadviser rates the domain 1 / 100 and Gridinsoft 0 / 100. The domain appears on one security blocklist and has been explicitly blocked by PhishDestroy. VirusTotal scans show that 16 of 95 antivirus and URL‑reputation engines flag the domain as malicious, providing independent corroboration of its threat status. The page title returned by the server is simply “1lnch.fi-v2.to”, offering no indication of a targeted brand or lure. Because the site is offline, active probing is limited, and the exact phishing kit or credential‑harvesting mechanism remains unknown.
The presence on a single external blocklist indicates limited community awareness, but the multi‑vendor detection on VirusTotal suggests a broader consensus of malicious intent. Absence of SSL and the generic page title further reduce legitimacy. The lack of publicly available Safe Browsing or OTX entries means that data sources may not yet have propagated the indicator, highlighting the need for manual IOC sharing. Defenders should continue to block the domain at perimeter firewalls and DNS filtering solutions, monitor for any re‑hosting attempts that may use the same IP or Cloudflare nameservers, and add the domain to internal threat‑intel feeds.
Señales de seguridad
Proceso de respuesta ante amenazas Pipeline
Estado de la lista de bloqueados pública
Análisis de VirusTotal
Datos y informes externos
¿Te ha afectado esta página web?
Si ingresó credenciales de cuenta, información personal o de pago, o descargó un archivo de este dominio, tome medidas inmediatas. A continuación encontrará recursos que le ayudarán a informar el incidente y protegerse.
Informa a las autoridades locales
Seleccione su país para obtener contactos oficiales de cibercrimen o crear un borrador de queja →.
Comprobar cualquier dominio
Análisis de amenazas utilizando listas de bloqueo almacenadas, WHOIS, DNS y evidencia de escaneo público
Escanear ahoraDenunciar un intento de phishing
Envía los dominios sospechosos a nuestra base de datos de amenazas: protege a la comunidad
DenunciarFlujo de amenazas en tiempo real
Informes de phishing recientes y cambios de disponibilidad observados
MonitorizarMantente informado, mantente a salvo
Supervisa las amenazas en tiempo real o impugna esta entrada si crees que se trata de un falso positivo.