MALICIOUS — CRITICAL
etv[.]az
Analysis of the domain etv.az indicates active credential phishing infrastructure posing as a cultural and educational portal.
- VirusTotal
- 3/91
- Blocklists
- No stored match
- Disponibilité
- Dernier actif connu · HTTP 200
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
etv.az — Dernier actif connu (HTTP 200). Résumé des preuves: VirusTotal 3/91 (alphaMountain.ai, CRDF, Gridinsoft); PhishDestroy score 76/100.
L’analyse détaillée de PhishDestroy AI reste en anglais afin de préserver le relevé forensique original.
Evidence Analysis
Analysis of the domain etv.az indicates active credential phishing infrastructure posing as a cultural and educational portal. The domain, registered on August 25, 1993, resolves to IP 162.241.225.93, hosted on AS46606 (Unified Layer) in the United States. The page title, 'etv.az-elm və mədəniyyət portalı – efirtv elm,' suggests an attempt to mimic a legitimate Azerbaijani cultural or media platform, though no confirmed brand impersonation is evident from available data. The site returns an HTTP 200 status, signaling an operational web presence. Technical indicators reveal mixed detection results: two of 93 security vendors on VirusTotal flag the domain, while PhishDestroy has already blocked it.
The domain appears on one security blocklist and is referenced in a single AlienVault OTX threat intelligence pulse. Gridinsoft assigns a trust score of 0/100, reinforcing suspicions of malicious intent. Detected technologies include WordPress, MySQL, PHP, Nginx, and Apache HTTP Server, which are commonly exploited in phishing campaigns for their ease of deployment and known vulnerabilities. SSL certification via Let's Encrypt (R12) is present, though this alone does not mitigate risk, as phishing sites frequently use valid certificates. Nameservers include az.hostmaster.ua, ns1.bluehost.com, ns2.bluehost.com, and rip.psg.com, with no immediate anomalies in DNS configuration.
The domain's long registration period (over 30 years) is unusual for phishing sites, which typically have short lifespans; however, this does not preclude compromise or repurposing of an older domain for malicious use. Defenders should treat etv.az as high-risk due to confirmed detections, blocklist presence, and low trust scores. Network-level blocking of the IP and domain is recommended, alongside monitoring for credential harvesting attempts originating from this infrastructure.
Couverture des données13 recorded checks
Signaux de sécurité
Processus de réponse aux menaces Pipeline
Statut de la liste de blocage publique
Technologies · 14 identified
Open-source CMS powering over 40% of websites worldwide.
Open-source relational database management system.
Server-side scripting language designed for web development.
Popular CSS framework for responsive, mobile-first web development.
High-performance HTTP server and reverse proxy, known for stability and low resource usage.
Most widely used open-source HTTP server software.
Touch-enabled jQuery plugin for responsive carousel sliders.
Plugin to detect and restore deprecated jQuery features.
Fast, small JavaScript library simplifying HTML manipulation, event handling, and Ajax.
Analyse VirusTotal
Preuves archivées
Analyse des performances du site
Google PageSpeed Insights — mobile performance audit of etv.az · checked Mar 2, 2026
Données factuelles et rapports externesIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
Si vous avez saisi des informations d'identification de compte, des informations personnelles ou de paiement, ou téléchargé un fichier à partir de ce domaine, agissez immédiatement. Vous trouverez ci-dessous des ressources pour vous aider à signaler l'incident et à vous protéger.
Signalez-le à vos autorités locales
Sélectionnez votre pays pour obtenir contacts officiels en matière de cybercriminalité ou créer un projet de plainte →.