backpackfashion[.]com
Résumé des preuves
The domain backpackfashion.com has been identified as a high-risk malicious domain associated with credential theft. This domain does not impersonate a specific brand but is designed to trick users into revealing sensitive information such as usernames, passwords, and personal data. The threat is significant due to the potential for widespread data compromise.
Infrastructure analysis reveals that backpackfashion.com is registered through NameSilo, LLC and was created on November 03, 2025. The domain resolves to the IP address 172.67.193.244, which is located in the United States and is part of the AS13335 Cloudflare, Inc. network. The domain lacks an SSL certificate, which is a common indicator of a non-secure and potentially malicious site. VirusTotal reports a score of 18/95, with 18 security vendors flagging the domain as malicious. The domain is currently listed on 3 security blocklists and has been taken offline according to recent checks.
The current status of backpackfashion.com is offline, which reduces the immediate risk of ongoing attacks. However, the domain remains a potential threat if it is reactivated or if residual phishing pages are still accessible through cached or archived versions. Security teams should monitor for any signs of reactivation and ensure that users are educated about the risks associated with credential theft. Additionally, any credentials that may have been compromised should be changed immediately, and users should be advised to enable multi-factor authentication (MFA) for added security.
Instantané des preuves transmises
- Envoyé
- Entrées du registre
- 1
- ID du dossier
PD-20260201-4EF675- Artefact PDF
- Preuve PDF
Fondement juridique
Texte intégral des preuves
Acceptable Use Policy (AUP): The domain backpackfashion.com is engaged in phishing activities, which constitutes a clear violation of your AUP prohibiting illegal activities, fraud, and deception.
Terms of Service (TOS): The use of this domain for fraudulent purposes directly contravenes your TOS, which reserves the right to suspend or terminate services for such violations.
Applicable Laws (Unknown):
Computer Fraud and Abuse Act (CFAA): This U.S. federal law prohibits unauthorized access to computers and the fraudulent use of information, which applies to phishing schemes.
Wire Fraud Statute (18 U.S.C. § 1343): This law criminalizes schemes to defraud individuals or entities using electronic communications, including phishing.
CAN-SPAM Act: This law regulates commercial email and prohibits deceptive practices, including misleading subject lines and sender information, which are common in phishing attacks.
Regulatory Note: Failure to take immediate action against this domain may result in regulatory scrutiny and potential liability under applicable laws. Non-compliance with your own policies could expose your organization to legal risks and reputational damage.
Data Coverage
Renseignements sur la sécurité réseau
Processus de réponse aux menaces Pipeline
Couverture des listes de blocage
10 sources externes surveillées · instantané du 11/08/2026
10 sources externes surveillées Aucune correspondance
Chronologie de détection
-
Cloudflare Radar
Analyse Cloudflare Radar enregistrée · Ouvrir l’analyse
Capture enregistrée
Informations sur les domaines
Détails techniquesDNS, noms TLS et horodatages
ICANN OVERSIGHT
Contexte de l’accréditation et du RAA
Contexte de l’accréditation et du RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Analyse VirusTotal
Ce site vous a-t-il affecté ?
Si vous avez saisi des informations d'identification de compte, des informations personnelles ou de paiement, ou téléchargé un fichier à partir de ce domaine, agissez immédiatement. Vous trouverez ci-dessous des ressources pour vous aider à signaler l'incident et à vous protéger.
Signalez-le à vos autorités locales
Sélectionnez votre pays pour obtenir contacts officiels en matière de cybercriminalité ou créer un projet de plainte →.
Vérifier n'importe quel domaine
Analyse des menaces à l'aide de listes de blocage stockées, de WHOIS, de DNS et de preuves d'analyse publique
Scanner maintenantSignaler une tentative d'hameçonnage
Signalez les domaines suspects à notre base de données des menaces — protégez la communauté
SignalerFlux d'alertes en temps réel
Rapports de phishing récents et changements de disponibilité observés
SurveillerRestez informés, restez en sécurité
Surveillez les menaces en temps réel ou signalez cette alerte si vous pensez qu'il s'agit d'un faux positif