capitalswestpoint[.]onnetw[.]com
“Welcome to Westpoint Capital | WestPoint Capitals”
capitalswestpoint.onnetw.com — Contenu indisponible. Usurpation de l'identité de la marque : Google; Type d'arnaque : Tech Support Scam. Résumé des preuves: VirusTotal 3/93 (alphaMountain.ai, Fortinet, Sophos); PhishDestroy score 71/100.
L’analyse détaillée de PhishDestroy AI reste en anglais afin de préserver le relevé forensique original.
Analysis of capitalswestpoint.onnetw.com shows a brand‑impersonation infrastructure targeting Google users through a tech‑support scam. The domain was registered on February 21, 2026 and resolves to the IP address 107.173.193.235, which is hosted in the United States under AS36352 (HostPapa). The TLS certificate presented is identified as R11, and the site’s page title reads “Welcome to Westpoint Capital | WestPoint Capitals,” which does not reference the targeted brand, indicating that the page’s visual content has not been disclosed. The domain is currently offline, having been taken down after detection. It appears on a single security blocklist and has been flagged by PhishDestroy.
Reputation scoring from Gridinsoft assigns a zero‑point trust rating (0/100). VirusTotal scans show three of ninety‑three security vendors reporting malicious activity, confirming that at least a subset of scanners recognize the domain as a threat. The threat level is classified as elevated. Defenders should immediately block the domain and its associated IP address at perimeter firewalls and DNS filtering solutions.
Email gateways should be configured to flag any messages containing references to the domain or the “Westpoint Capital” title. Continuous monitoring of the hosting provider (HostPapa) for new domains that resolve to the same IP range is advised, as the actor may re‑host future campaigns. Since the site’s internal content has not been publicly analyzed, threat‑intel teams should treat any newly observed page elements with heightened suspicion and prioritize sandbox analysis if the site reappears. Updating threat‑feed subscriptions to include the domain’s hash and associated indicators will help ensure rapid detection of any resurgence.
Processus de réponse aux menaces Pipeline
Statut de la liste de blocage publique
Analyse forensique
Analyse VirusTotal
Données factuelles et rapports externes
Ce site vous a-t-il affecté ?
Si vous avez saisi des informations d'identification de compte, des informations personnelles ou de paiement, ou téléchargé un fichier à partir de ce domaine, agissez immédiatement. Vous trouverez ci-dessous des ressources pour vous aider à signaler l'incident et à vous protéger.
Signalez-le à vos autorités locales
Sélectionnez votre pays pour obtenir contacts officiels en matière de cybercriminalité ou créer un projet de plainte →.
Vérifier n'importe quel domaine
Analyse des menaces à l'aide de listes de blocage stockées, de WHOIS, de DNS et de preuves d'analyse publique
Scanner maintenantSignaler une tentative d'hameçonnage
Signalez les domaines suspects à notre base de données des menaces — protégez la communauté
SignalerFlux d'alertes en temps réel
Rapports de phishing récents et changements de disponibilité observés
SurveillerRestez informés, restez en sécurité
Surveillez les menaces en temps réel ou signalez cette alerte si vous pensez qu'il s'agit d'un faux positif