MALICIOUS — HIGH
Análisis de phishing y seguridad de ubnr.cc
ubnr[.]
The domain ubnr.cc was registered on February 21, 2026 and is currently taken offline.
- VirusTotal
- 2/93
- Blocklists
- 2 · ScamSniffer, Enkrypt
- Disponibilidad
- Contenido no disponible · HTTP 502
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
ubnr.cc — Contenido no disponible (HTTP 502). Suplantación de marca: Google; Tipo de estafa: Tech Support Scam. Resumen de las pruebas: VirusTotal 2/93 (alphaMountain.ai, Forcepoint ThreatSeeker); 2 external blocklist matches (ScamSniffer, Enkrypt); PhishDestroy score 66/100.
El análisis detallado de PhishDestroy AI se mantiene en inglés para conservar el registro forense original.
Evidence Analysis
The domain ubnr.cc was registered on February 21, 2026 and is currently taken offline. Infrastructure analysis shows it resolves to the IPv6 address 2606:4700:20::681a:8c8, which is hosted by Cloudflare, Inc. (AS13335) in the United States. The site presents a page titled "Solflare" and is classified as a tech support scam that attempts to impersonate Google. Multiple security feeds have flagged the domain: PhishDestroy, ScamSniffer, and Enkrypt have all blocked it, and it appears on three additional blocklists.
VirusTotal scans indicate that two of ninety‑three security vendors flagged the domain as malicious, reinforcing the suspicion of abuse. Reputation services assign low trust scores, with Scamadviser rating the site at 31 out of 100 and Gridinsoft reporting a score of zero, reflecting a high likelihood of fraudulent activity. The SSL certificate associated with ubnr.cc is identified as grade E1, which provides minimal assurance of authenticity.
Although the site is no longer reachable, the observed indicators—hosted on a cloud provider, low trust metrics, a page title unrelated to the targeted brand, and detection by several anti‑phishing platforms—suggest a coordinated attempt to lure victims into a Google‑impersonating tech support scheme. Defenders should continue to block the domain at network perimeters, update URL filtering and threat intelligence feeds with the IPv6 address and associated hostnames, and monitor for any re‑use of the same infrastructure in future campaigns. Incident response teams should also advise users to disregard unsolicited Google‑related support requests and verify communications through official channels.
Stored source results
Recorded verdicts and infrastructure observations for this domain.
Cobertura de los datos13 recorded checks
Proceso de respuesta ante amenazas Pipeline
Estado de la lista de bloqueados pública
Inteligencia forense
Análisis de VirusTotal
Datos y informes externosIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
Si ingresó credenciales de cuenta, información personal o de pago, o descargó un archivo de este dominio, tome medidas inmediatas. A continuación encontrará recursos que le ayudarán a informar el incidente y protegerse.
Informa a las autoridades locales
Seleccione su país para obtener contactos oficiales de cibercrimen o crear un borrador de queja →.