cl469886-wordpress-ipv4q[.]tw1[.]ru
“Домен припаркован в Timeweb”
cl469886-wordpress-ipv4q.tw1.ru — No verificado. Resumen de las pruebas: VirusTotal 14/91 (ADMINUSLabs, alphaMountain.ai, BitDefender, Chong Lua Dao, CyRadar); Google Safe Browsing flagged; CF Radar malicious; PhishDestroy score 98/100.
El análisis detallado de PhishDestroy AI se mantiene en inglés para conservar el registro forense original.
This domain, cl469886-wordpress-ipv4q.tw1.ru, is currently flagged as an active phishing threat targeting users through a WordPress-themed lure. Analysis indicates the domain was registered on February 21, 2026, and resolves to 92.53.96.105, an IP address hosted within AS9123 (JSC TIMEWEB) in Russia. The infrastructure is consistent with a parked domain setup, as evidenced by the page title 'Домен припаркован в Timeweb' and nameservers under Timeweb’s control. However, the inclusion of 'wordpress' in the subdomain suggests an attempt to mimic legitimate WordPress hosting, a common tactic in phishing campaigns to deceive users into believing the site is associated with a trusted platform. Technical indicators reinforce the phishing classification. The domain is blocked by two security blocklists, including PhishDestroy and PhishingDB, and is flagged by Google Safe Browsing for social engineering. Twelve out of ninety-five security vendors on VirusTotal have detected malicious activity associated with this domain, though the specific payload or phishing kit remains unconfirmed. The SSL certificate, issued by GlobalSign, provides basic encryption but does not validate the legitimacy of the site’s content. MX records point to Timeweb’s mail servers, which could be leveraged for credential harvesting or further phishing distribution. Defenders should treat this domain as high-risk due to its active status and confirmed presence on multiple blocklists. The 302 HTTP redirect suggests the domain may be part of a larger redirection chain, potentially leading to a phishing landing page or malware distribution. Organizations should block traffic to and from 92.53.96.105 and monitor for any attempts to exploit the WordPress branding in the subdomain. Given the domain’s recent registration and lack of legitimate content, it is unlikely to serve a benign purpose. Additional scrutiny of Timeweb-hosted domains with similar naming patterns may reveal related threats.
Inteligencia de seguridad de red
Proceso de respuesta ante amenazas Pipeline
Estado de la lista de bloqueados pública
Análisis de VirusTotal
Datos y informes externos
¿Te ha afectado esta página web?
Si ingresó credenciales de cuenta, información personal o de pago, o descargó un archivo de este dominio, tome medidas inmediatas. A continuación encontrará recursos que le ayudarán a informar el incidente y protegerse.
Informa a las autoridades locales
Seleccione su país para obtener contactos oficiales de cibercrimen o crear un borrador de queja →.
Comprobar cualquier dominio
Análisis de amenazas utilizando listas de bloqueo almacenadas, WHOIS, DNS y evidencia de escaneo público
Escanear ahoraDenunciar un intento de phishing
Envía los dominios sospechosos a nuestra base de datos de amenazas: protege a la comunidad
DenunciarFlujo de amenazas en tiempo real
Informes de phishing recientes y cambios de disponibilidad observados
MonitorizarMantente informado, mantente a salvo
Supervisa las amenazas en tiempo real o impugna esta entrada si crees que se trata de un falso positivo.