MALICIOUS — CRITICAL
Análisis de phishing y seguridad de leacrocodile.com
leacrocodile[.]
Analysis of leacrocodile.com indicates that the domain was registered on March 23, 2026 through Dominet (HK) Limited and is currently hosted behind Cloudflare, Inc.
- VirusTotal
- 13/91
- Blocklists
- No stored match
- Disponibilidad
- Contenido no disponible · HTTP 502
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
leacrocodile.com — Contenido no disponible (HTTP 502). Tipo de estafa: Credential Phishing. Resumen de las pruebas: VirusTotal 13/91 (ADMINUSLabs, alphaMountain.ai, BitDefender, CRDF, CyRadar); PhishDestroy score 89/100. Registrador: Dominet (HK).
El análisis detallado de PhishDestroy AI se mantiene en inglés para conservar el registro forense original.
Evidence Analysis
Analysis of leacrocodile.com indicates that the domain was registered on March 23, 2026 through Dominet (HK) Limited and is currently hosted behind Cloudflare, Inc. The authoritative nameservers are konnor.ns.cloudflare.com and sharon.ns.cloudflare.com, and the domain resolves to IP address 188.114.96.3, which is geolocated to Canada. The site served an HTTPS certificate issued by Let’s Encrypt and employed technologies typical of a Microsoft ASP.NET stack, including jQuery, Cloudflare Browser Insights, and HTTP/3. The only visible page element is the title "Connectez-vous à votre compte," which aligns with the classified scam type of credential phishing. VirusTotal scans show that two of ninety‑four security vendors flagged the domain, and it appears on a single external blocklist.
PhishDestroy has also listed the domain as blocked. The domain’s status is reported as offline, suggesting the phishing infrastructure has been taken down or is temporarily dormant. However, the underlying hosting arrangement with Cloudflare and the use of a public certificate mean that the infrastructure could be re‑activated quickly.
Defenders should continue to deny traffic to 188.114.96.3 and monitor for any re‑registration of the domain or related sub‑domains. Adding leacrocodile.com to local blocklists, updating firewall deny rules, and reporting the indicator to threat‑sharing platforms will reduce exposure. Continuous observation of Cloudflare‑associated IP ranges for similar ASP.NET‑based phishing payloads is recommended, as the same hosting provider may be leveraged for future campaigns.
Stored source results
Recorded verdicts and infrastructure observations for this domain.
Cobertura de los datos12 recorded checks
Proceso de respuesta ante amenazas Pipeline
Estado de la lista de bloqueados pública
Captura guardada
Inteligencia de dominios
Detalles técnicosDNS, SAN de SSL, marcas de tiempo
ICANN OVERSIGHT
Acreditación y contexto RAA
Acreditación y contexto RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Tecnologías · 5 identified
Fast, small JavaScript library simplifying HTML manipulation, event handling, and Ajax.
Performance monitoring tool that measures website speed from real users.
www.cloudflare.comWeb infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
Análisis de VirusTotal
Análisis del rendimiento del sitio
Google PageSpeed Insights — mobile performance audit of leacrocodile.com · checked Mar 23, 2026
Datos y informes externosIndependent lookups and source reports
PD-20260323-3C16F1 Recipient: domainabuse@service.aliyun.com Victim safety and official reportingImmediate actions and verified reporting channels
Si ingresó credenciales de cuenta, información personal o de pago, o descargó un archivo de este dominio, tome medidas inmediatas. A continuación encontrará recursos que le ayudarán a informar el incidente y protegerse.
Informa a las autoridades locales
Seleccione su país para obtener contactos oficiales de cibercrimen o crear un borrador de queja →.