finance-portfolio[.]icu
“404 Not Found”
finance-portfolio.icu — Contenu indisponible. Résumé des preuves: VirusTotal 5/93 (alphaMountain.ai, CyRadar, Forcepoint ThreatSeeker, Fortinet, SOCRadar); Spamhaus DBL_PHISH; 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 70/100.
L’analyse détaillée de PhishDestroy AI reste en anglais afin de préserver le relevé forensique original.
The domain finance-portfolio.icu was registered on February 23, 2026 and is currently taken offline. DNS resolution points to 172.67.187.89, an address owned by Cloudflare, Inc. (AS13335) and geolocated to the United States. The site presents a 404 Not Found page title, indicating that no landing content is presently served. An SSL certificate labeled WE1 is in place, showing that TLS was configured despite the lack of active content.
Reputation scoring is extremely low, with Gridinsoft assigning a trust score of 0 out of 100. VirusTotal scans report that five of ninety‑three security vendors flagged the domain, suggesting that at least a minority of AV engines detected malicious characteristics. The domain is listed on three public blocklists and is actively blocked by PhishDestroy, MetaMask, and SEAL, reinforcing the view that it has been used for phishing‑related activity.
While the specific brand or service being impersonated has not been identified in the available intelligence, the combination of a newly created domain, Cloudflare hosting, low trust rating, and multiple blocklist entries aligns with typical infrastructure used for credential‑harvesting or fraud campaigns. Defenders should continue to block finance-portfolio.icu at perimeter controls, monitor for any future DNS resolution changes, and update intrusion‑detection signatures to include the associated IP address and SSL fingerprint. Because the site is offline, there is no immediate payload to analyze, but the observed indicators warrant inclusion in threat‑intel feeds and ongoing watchlists for potential re‑activation.
Processus de réponse aux menaces Pipeline
Statut de la liste de blocage publique
Capture enregistrée
Informations sur les domaines
Détails techniquesDNS, SAN SSL, horodatages
ZONE SHORTDOT · PREUVES PUBLIQUES
.icu
ShortDot zone evidence
ShortDot zone evidence
The linked repository preserves daily zone observations across seven ShortDot-operated TLDs, including registration volume and abuse-related indicators. This registry context is supporting background and is not an independent detection for the domain in this report.
Analyse forensique
Analyse VirusTotal
Données factuelles et rapports externes
Ce site vous a-t-il affecté ?
Si vous avez saisi des informations d'identification de compte, des informations personnelles ou de paiement, ou téléchargé un fichier à partir de ce domaine, agissez immédiatement. Vous trouverez ci-dessous des ressources pour vous aider à signaler l'incident et à vous protéger.
Signalez-le à vos autorités locales
Sélectionnez votre pays pour obtenir contacts officiels en matière de cybercriminalité ou créer un projet de plainte →.
Vérifier n'importe quel domaine
Analyse des menaces à l'aide de listes de blocage stockées, de WHOIS, de DNS et de preuves d'analyse publique
Scanner maintenantSignaler une tentative d'hameçonnage
Signalez les domaines suspects à notre base de données des menaces — protégez la communauté
SignalerFlux d'alertes en temps réel
Rapports de phishing récents et changements de disponibilité observés
SurveillerRestez informés, restez en sécurité
Surveillez les menaces en temps réel ou signalez cette alerte si vous pensez qu'il s'agit d'un faux positif