f[.]v1-network[.]run
“403 Forbidden”
Analysis indicates that the domain f.v1-network.run is associated with a Seed Phrase Phishing campaign. The domain was registered on December 18, 2025 through NiceNIC International Group Co., Limited and currently resolves to the IP address 172.67.188.89, which belongs to Cloudflare, Inc. (AS13335) and is geolocated in the United States. DNS resolution is handled by the Cloudflare nameservers bingo.ns.cloudflare.com and curt.ns.cloudflare.com, confirming the use of Cloudflare's infrastructure for both DNS and content delivery. No TLS certificate was presented during connection attempts; the HTTP request returned a 403 Forbidden status, and the site is presently offline, which aligns with the reported status of the domain being taken offline.
VirusTotal analysis recorded five detections out of ninety‑five security vendors, providing independent confirmation of malicious behavior. The domain is listed on one security blocklist and is actively blocked by the PhishDestroy service. Independent scoring from Gridinsoft assigned a trust score of 0 out of 100, further indicating a high likelihood of abuse. The risk level for this infrastructure is elevated.
Uncertainties remain regarding the exact HTML content, victim brand, and phishing lure because the site returns a 403 error and no visual artifacts have been captured. Defenders should block the domain and its associated IP at perimeter firewalls, incorporate the domain into URL filtering policies, and monitor DNS queries for any future resolution attempts. Continuous re‑scanning of the domain is advised to detect possible re‑hosting, and sharing of these indicators with broader threat‑intel communities will aid in collective mitigation efforts.
Renseignements sur la sécurité réseau Registrar context
Processus de réponse aux menaces Pipeline
Couverture des listes de blocage
10 sources · synchronisées le 10/08/2026
Chronologie de détection
Observations enregistrées par ordre chronologique.
-
Cloudflare Radar
Cloudflare Radar : observé pour la première fois comme https://radar.cloudflare.com/scan/f3521df6-6636-4075-945b-29067b72ab83
-
Disponibilité
Disponibilité : observé pour la première fois comme dns_inactive
f93a11f87e4d -
Disponibilité
Disponibilité : dns_inactive → unknown
030739084df7 -
Disponibilité
Disponibilité : unknown → inactive
cba6f26fe060 -
Disponibilité
Disponibilité : inactive → dns_inactive
bb2519d2d5df -
Disponibilité
Disponibilité : dns_inactive → held
619ede905869 -
Disponibilité
Disponibilité : held → dns_inactive
f52d526b76a1 -
Disponibilité
Disponibilité : dns_inactive → unknown
8983d61182f0 -
Disponibilité
Disponibilité : unknown → held
ceaf864b416d -
Disponibilité
Disponibilité : held → unknown
ced0700fa377
Tout afficher (8)
-
Disponibilité
Disponibilité : unknown → dns_inactive
6dfe9145995c -
Disponibilité
Disponibilité : dns_inactive → held
fe3413bf0bec -
Disponibilité
Disponibilité : held → dns_inactive
641ed81dc4d5 -
Disponibilité
Disponibilité : dns_inactive → unknown
98f23e87f6dd -
Disponibilité
Disponibilité : unknown → held
3ac3b7c5551f -
Disponibilité
Disponibilité : held → unknown
8d257e5ff103 -
Disponibilité
Disponibilité : unknown → dns_inactive
d0b7046e8c2f -
Disponibilité
Disponibilité : dns_inactive → held
87145449ee6e
Capture enregistrée
Informations sur les domaines
Détails techniquesDNS, noms TLS et horodatages
ICANN OVERSIGHT
Registration: v1-network.run
Contexte de l’accréditation et du RAA
Contexte de l’accréditation et du RAA
Registrar accreditation and DNS abuse obligations
For the registrable domain v1-network.run behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Analyse VirusTotal
Ce site vous a-t-il affecté ?
Si vous avez saisi des informations d'identification de compte, des informations personnelles ou de paiement, ou téléchargé un fichier à partir de ce domaine, agissez immédiatement. Vous trouverez ci-dessous des ressources pour vous aider à signaler l'incident et à vous protéger.
Signalez-le à vos autorités locales
Sélectionnez votre pays pour obtenir contacts officiels en matière de cybercriminalité ou créer un projet de plainte →.
Vérifier n'importe quel domaine
Analyse des menaces à l'aide de listes de blocage stockées, de WHOIS, de DNS et de preuves d'analyse publique
Scanner maintenantSignaler une tentative d'hameçonnage
Signalez les domaines suspects à notre base de données des menaces — protégez la communauté
SignalerFlux d'alertes en temps réel
Rapports de phishing récents et changements de disponibilité observés
SurveillerRestez informés, restez en sécurité
Surveillez les menaces en temps réel ou signalez cette alerte si vous pensez qu'il s'agit d'un faux positif