cs880817-wordpress-f5a04[.]tw1[.]ru
“Домен припаркован в Timeweb”
cs880817-wordpress-f5a04.tw1.ru — Non vérifié. Usurpation de l'identité de la marque : Wordpress; Type d'arnaque : Brand Impersonation. Résumé des preuves: VirusTotal 14/91 (ADMINUSLabs, alphaMountain.ai, BitDefender, CyRadar, ESET); Google Safe Browsing flagged; CF Radar malicious; PhishDestroy score 97/100. Bureau d’enregistrement: TW-Cloud (ASN: 9123).
L’analyse détaillée de PhishDestroy AI reste en anglais afin de préserver le relevé forensique original.
This domain, cs880817-wordpress-f5a04.tw1.ru, is actively flagged as a high-risk brand impersonation threat targeting WordPress. Analysis indicates the domain is registered through TW-Cloud (ASN 9123) and currently resolves to the IPv6 address 2a03:6f00:1::5c35:6069. The page title, 'Домен припаркован в Timeweb,' suggests it may be hosted on a parked domain service, though the exact content remains unanalyzed. Security vendors have detected malicious indicators, with 12 out of 95 engines on VirusTotal flagging the domain, and it appears on two security blocklists, including PhishDestroy and PhishingDB. The domain is explicitly categorized as engaging in social engineering, as confirmed by Google Safe Browsing. Its Gridinsoft trust score of 0/100 and Scamadviser trust score of 1/100 further corroborate its high-risk classification. The SSL certificate is issued by GlobalSign nv-sa, which does not mitigate the underlying threat but may lend a superficial appearance of legitimacy. No specific phishing kit or payload has been identified in the available data, leaving the exact attack vector uncertain. Defenders should treat this domain as an active threat. Immediate action includes blocking the domain and its resolving IP at the network perimeter, as well as monitoring for any internal connections to it. Given the domain's association with brand impersonation and social engineering, user awareness training may be warranted to prevent potential credential harvesting or malware distribution. The domain remains active as of July 12, 2026, and should be prioritized for further investigation if any internal systems have interacted with it. No evidence suggests this is part of a larger campaign, but its registration through a known hosting provider warrants scrutiny of related infrastructure.
Signaux de sécurité
Renseignements sur la sécurité réseau
Processus de réponse aux menaces Pipeline
Statut de la liste de blocage publique
Analyse VirusTotal
Preuves archivées
Données factuelles et rapports externes
Ce site vous a-t-il affecté ?
Si vous avez saisi des informations d'identification de compte, des informations personnelles ou de paiement, ou téléchargé un fichier à partir de ce domaine, agissez immédiatement. Vous trouverez ci-dessous des ressources pour vous aider à signaler l'incident et à vous protéger.
Signalez-le à vos autorités locales
Sélectionnez votre pays pour obtenir contacts officiels en matière de cybercriminalité ou créer un projet de plainte →.
Vérifier n'importe quel domaine
Analyse des menaces à l'aide de listes de blocage stockées, de WHOIS, de DNS et de preuves d'analyse publique
Scanner maintenantSignaler une tentative d'hameçonnage
Signalez les domaines suspects à notre base de données des menaces — protégez la communauté
SignalerFlux d'alertes en temps réel
Rapports de phishing récents et changements de disponibilité observés
SurveillerRestez informés, restez en sécurité
Surveillez les menaces en temps réel ou signalez cette alerte si vous pensez qu'il s'agit d'un faux positif