berlusconi-cc[.]to
“Berlusconi || Berlusconi Login || berlusconi-cc.to || Berlusconi Market”
berlusconi-cc.to — Contenu indisponible. Type d'arnaque : Credential Phishing. Résumé des preuves: VirusTotal 3/91 (CRDF, Gridinsoft, SOCRadar); PhishDestroy score 71/100. Bureau d’enregistrement: Government of Kingdom ….
L’analyse détaillée de PhishDestroy AI reste en anglais afin de préserver le relevé forensique original.
The domain berlusconi-cc.to is currently active and was registered on October 15, 2025 through the Government of the Kingdom of Tonga. It resolves to the Cloudflare IP address 172.67.70.170, which is geolocated to Canada, and presents a valid SSL certificate issued by Google Trust Services (WE1). An HTTP request to the site returns a 200 status code and the page title reads "Berlusconi || Berlusconi Login || berlusconi-cc.to || Berlusconi Market," indicating an attempt to mimic a legitimate service.
Infrastructure analysis reveals a modern web stack built on Node.js, employing Next.js, Express, React, Bootstrap, and Webpack, with Google Analytics embedded for traffic tracking. The domain is served behind Cloudflare, using the nameservers norman.ns.cloudflare.com and zariyah.ns.cloudflare.com. Reputation services assign a Gridinsoft trust score of 0 out of 100, and VirusTotal reports three detections out of ninety‑five security vendors, confirming malicious indicators. The domain appears on one public blocklist and is actively blocked by PhishDestroy.
Based on the observed page title, low trust score, and vendor detections, the site is classified as a credential phishing operation targeting users who may believe they are accessing a "Berlusconi" service. The evidence points to a deliberate credential‑harvesting campaign, though the limited number of blocklist entries leaves the full scope of distribution uncertain.
Defenders should add berlusconi-cc.to to DNS blocklists and enforce URL filtering to prevent access. Network monitoring should flag any outbound connections to the IP 172.67.70.170, and email security solutions must flag messages containing this domain. Organizations should assume any credentials submitted to the site are compromised and advise users to change affected passwords immediately. Ongoing surveillance of related Cloudflare‑hosted assets is recommended to detect potential expansions of the campaign.
Processus de réponse aux menaces Pipeline
Statut de la liste de blocage publique
Analyse forensique
Technologies · 8 identified
JavaScript runtime built on Chrome V8 engine for server-side development.
Popular CSS framework for responsive, mobile-first web development.
JavaScript library for building user interfaces with component-based architecture.
React framework for production with hybrid static and server rendering.
Web analytics service tracking website traffic and user behavior.
marketingplatform.google.comWeb infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comModule bundler for modern JavaScript applications.
Analyse VirusTotal
Preuves archivées
Analyse des performances du site
Google PageSpeed Insights — mobile performance audit of berlusconi-cc.to · checked Mar 27, 2026
Données factuelles et rapports externes
PD-20260324-7E2003 Recipient: abuse@tonic.to Ce site vous a-t-il affecté ?
Si vous avez saisi des informations d'identification de compte, des informations personnelles ou de paiement, ou téléchargé un fichier à partir de ce domaine, agissez immédiatement. Vous trouverez ci-dessous des ressources pour vous aider à signaler l'incident et à vous protéger.
Signalez-le à vos autorités locales
Sélectionnez votre pays pour obtenir contacts officiels en matière de cybercriminalité ou créer un projet de plainte →.
Vérifier n'importe quel domaine
Analyse des menaces à l'aide de listes de blocage stockées, de WHOIS, de DNS et de preuves d'analyse publique
Scanner maintenantSignaler une tentative d'hameçonnage
Signalez les domaines suspects à notre base de données des menaces — protégez la communauté
SignalerFlux d'alertes en temps réel
Rapports de phishing récents et changements de disponibilité observés
SurveillerRestez informés, restez en sécurité
Surveillez les menaces en temps réel ou signalez cette alerte si vous pensez qu'il s'agit d'un faux positif