state[.]ewqpay[.]cc
“ewqpay.cc | 520: Web server is returning an unknown error”
Resumen de las pruebas
Analysis of state.ewqpay.cc indicates an active phishing domain targeting payment processing systems. The domain was registered on September 21, 2025, through Dominet (HK) Limited, a registrar frequently associated with fraudulent infrastructure. As of July 29, 2026, the domain resolves to IP address 172.67.218.44, which is part of a network range commonly used for content delivery and proxy services, potentially obscuring the true origin of the malicious activity. VirusTotal telemetry reports that 6 out of 91 security vendors flag state.ewqpay.cc as malicious, suggesting moderate but not universal detection.
The domain appears on one additional security blocklist, and it is currently blocked by PhishDestroy, a specialized anti-phishing service. No data from Google Safe Browsing, AlienVault OTX, or other threat intelligence platforms is available at this time, limiting visibility into broader detection patterns or historical abuse. Infrastructure analysis reveals no SSL certificate details or HTTP response codes, leaving the operational status of the phishing page uncertain.
The exact content and targeted brand remain unconfirmed, as no page title or kit identification is available in the current evidence. Defenders should treat state.ewqpay.cc as an elevated-risk domain due to its registration context, detection by multiple vendors, and association with payment-themed phishing. Network-level blocking of 172.67.218.44 and monitoring for related subdomains under ewqpay.cc are recommended until further analysis clarifies the scope of the campaign.
Data Coverage
Inteligencia de seguridad de red
Proceso de respuesta ante amenazas Pipeline
Cobertura de listas de bloqueo
10 fuentes externas supervisadas · instantánea del 11/08/2026
10 fuentes externas supervisadas Sin coincidencias
Cronología de detección
-
VirusTotal
4 → 5
-
Estado del dominio
Accesible → Inaccesible
Inteligencia de dominios
Detalles técnicosDNS, nombres TLS y marcas de tiempo
Análisis de VirusTotal
¿Te ha afectado esta página web?
Si ingresó credenciales de cuenta, información personal o de pago, o descargó un archivo de este dominio, tome medidas inmediatas. A continuación encontrará recursos que le ayudarán a informar el incidente y protegerse.
Informa a las autoridades locales
Seleccione su país para obtener contactos oficiales de cibercrimen o crear un borrador de queja →.
Comprobar cualquier dominio
Análisis de amenazas utilizando listas de bloqueo almacenadas, WHOIS, DNS y evidencia de escaneo público
Escanear ahoraDenunciar un intento de phishing
Envía los dominios sospechosos a nuestra base de datos de amenazas: protege a la comunidad
DenunciarFlujo de amenazas en tiempo real
Informes de phishing recientes y cambios de disponibilidad observados
MonitorizarMantente informado, mantente a salvo
Supervisa las amenazas en tiempo real o impugna esta entrada si crees que se trata de un falso positivo.