confirmation-id40944[.]com
Análisis de phishing y seguridad de confirmation-id40944.com
“ååè¿æ”
confirmation-id40944.com — Contenido no disponible (HTTP 502). Tipo de estafa: Credential Phishing. Resumen de las pruebas: VirusTotal 14/91 (ADMINUSLabs, alphaMountain.ai, BitDefender, Chong Lua Dao, CyRadar); Spamhaus DBL_PHISH; PhishDestroy score 98/100. Registrador: Dominet (HK).
El análisis detallado de PhishDestroy AI se mantiene en inglés para conservar el registro forense original.
This domain, confirmation-id40944.com, is flagged as a generic phishing resource specializing in credential harvesting. Analysis indicates no direct brand impersonation, suggesting a broad-spectrum approach targeting login credentials across multiple platforms. The infrastructure appears designed to mimic authentication portals, likely using static HTML forms to capture submitted credentials without immediate validation, a common tactic in low-sophistication phishing kits. Infrastructure analysis reveals the following technical indicators: the domain is registered through Dominet (HK) Limited and was created on June 24, 2025. VirusTotal detection shows 14 out of 95 security vendors flagging the domain as malicious. The domain appears on one security blocklist and is currently not listed in Google Safe Browsing. No associated IP address or hosting provider has been confirmed in available data, limiting attribution at this stage. The domain remains active as of the latest verification, with no takedown actions observed. Users encountering this domain are advised to avoid interaction and report it to their security teams. Organizations should update blocklists to include this domain and monitor for credential reuse attempts from affected accounts. Given the domain's recent registration and low detection rate, heightened vigilance is recommended for potential victims.
Proceso de respuesta ante amenazas Pipeline
Estado de la lista de bloqueados pública
Inteligencia de dominios
Detalles técnicosDNS, SAN de SSL, marcas de tiempo
ICANN OVERSIGHT
Acreditación y contexto RAA
Acreditación y contexto RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Análisis de VirusTotal
Datos y informes externos
¿Te ha afectado esta página web?
Si ingresó credenciales de cuenta, información personal o de pago, o descargó un archivo de este dominio, tome medidas inmediatas. A continuación encontrará recursos que le ayudarán a informar el incidente y protegerse.
Informa a las autoridades locales
Seleccione su país para obtener contactos oficiales de cibercrimen o crear un borrador de queja →.
Comprobar cualquier dominio
Análisis de amenazas utilizando listas de bloqueo almacenadas, WHOIS, DNS y evidencia de escaneo público
Escanear ahoraDenunciar un intento de phishing
Envía los dominios sospechosos a nuestra base de datos de amenazas: protege a la comunidad
DenunciarFlujo de amenazas en tiempo real
Informes de phishing recientes y cambios de disponibilidad observados
MonitorizarMantente informado, mantente a salvo
Supervisa las amenazas en tiempo real o impugna esta entrada si crees que se trata de un falso positivo.