Aller au rapport de sécurité
Checked 09/08/2026 Ref 87D1CE4F

MALICIOUS — HIGH

Analyse phishing et sécurité de firstcallcover.com

firstcallcover[.]com

This domain poses a significant threat as a generic credential theft site, designed to trick users into divulging sensitive information.

69/100 evidence score · High
VirusTotal
3/91
Blocklists
No stored match
Disponibilité
Dernier actif connu · HTTP 302
Report / Add Evidence Appeal this listing
No capture stored

Do not enter credentials, seed phrases, payment details, or personal information on this domain.

⚠️
Ce domaine a été signalé comme malveillant
Moteurs de sécurité signalant une détection : 3. Faites preuve d’une extrême prudence – ne saisissez pas d’informations d’identification ou d’informations personnelles.
Jump to section
Résumé du rapport

firstcallcover.com — Dernier actif connu (HTTP 302). Type d'arnaque : Credential Phishing. Résumé des preuves: VirusTotal 3/91 (CRDF, Gridinsoft, SOCRadar); PhishDestroy score 69/100. Bureau d’enregistrement: Fewmoretaps OU d/b/a T….

L’analyse détaillée de PhishDestroy AI reste en anglais afin de préserver le relevé forensique original.

Evidence Analysis

Ref 87D1CE4F

This domain poses a significant threat as a generic credential theft site, designed to trick users into divulging sensitive information. PhishDestroy identifies the threat as particularly insidious due to its ability to blend in with legitimate sites, with 0 out of 95 VirusTotal scanners flagging it as malicious, registered through Fewmoretaps OU d/b/a Trustname.com on April 28, 2026, and currently appearing on 1 security blocklist.

The domain's creation date and its resolution to IP 185.113.8.69 are key factors in assessing its risk, with the registrar information and blocklist count of 1 providing crucial evidence of its potential for harm, now taken offline.

Users who may have visited firstcallcover.com should immediately take steps to secure their online accounts and monitor their financial transactions, given the site's specific threat of credential theft, and report any suspicious activity, as the site's offline status does not negate the potential damage already done, emphasizing the need for vigilance and prompt action to protect sensitive information.

Stored source results

Recorded verdicts and infrastructure observations for this domain.

VirusTotal
VirusTotal
3 det.
OTX references
Certificat TLS
Google Trust Services / WE1
Âge
3 mo
Statut observé
Dernier actif connu 302
PhishDestroy
DestroyList
Répertorié
Couverture des données12 recorded checks
VirusTotal 3 / 91 URLQuery pas vérifié PhishStats pas vérifié OTX 23 community references CF Radar no data URLScan capture not submitted URLScan verdict verdict indisponible Blocs DNS pas vérifié TLS valid certificate, 62d WHOIS 3 mo old Capture d'écran non capturé Chaîne de redirection non sondé
Renseignements sur la sécurité réseau Registrar context
Registrar context Trustname
Stored registration data identifies Trustname / Fewmoretaps OÜ (IANA 4318) as the registrar. PhishDestroy maintains a separate registrar investigation; that material is contextual and is not an independent detection for this domain.
Trustname Investigation

Processus de réponse aux menaces Pipeline

Découverte
Checks
Reports
Disponibilité
7/9
Menace détectée
firstcallcover.com détectés et mis en file d'attente en vue d'une analyse complète
15/06/2026
VirusTotal
3/91 recorded on VirusTotal
05/08/2026
Google Safe Browsing
27/07/2026
OTX Community References
23 community publication references on AlienVault OTX. References are not vendor verdicts and are excluded from the evidence score.
27/07/2026
Registrar Context: Trustname
Separate registrar research is available. Registrar association is contextual and is not scored as an independent detection.
Technical Analysis Recorded
Le rapport contient des résultats de technologie ou d’analyse médico-légale stockés.
09/08/2026
Complaint Draft Available
Aucune soumission n'est enregistrée. Vous pouvez créer un brouillon, le réviser et le soumettre vous-même à l'autorité compétente.
DestroyList publié
15/06/2026
Monitoring Continues
Le domaine reste accessible ou restreint en accès ; des contrôles futurs pourraient mettre à jour cette observation.

Statut de la liste de blocage publique

Informations sur les domaines

Domaine
Serveur / ASN cloudflare · AS200019 ALEXHOST SRL
IP Context Cloudflare shared edge origin IP hidden La réputation Edge-IP n’est pas attribuée à ce domaine.
Bureau d’enregistrement Fewmoretaps OU d/b/a T… BY(BY) PhishDestroy Investigation
Adresse IP 185.113.8.69 CDN
LocalisationNL Almere Stad, NL
RéseauAS200019 · Alexhost SRL
L'adresse IP d'origine est cachée derrière un proxy CDN. Les résultats d’IP inversé pour l’adresse périphérique contiennent des locataires non liés ; trouver l’origine nécessite un DNS passif ou des données de transparence des certificats.
EnregistrementCréé 28/04/2026 (102d)
Statut HTTP302 Found (Temporary)
Détails techniquesDNS, SAN SSL, horodatages
Première détection15/06/2026
Serveurs de nomsseth.ns.cloudflare.com
TLS Fingerprint
TLS Observationvalid from 12/07/2026scanned 02/08/2026
ICANN OVERSIGHT

Contexte de l’accréditation et du RAA

Registrar accreditation and DNS abuse obligations

For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.

Accreditation is a contract, not a safety certification.

RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.

Accountability draft Rien n’est envoyé automatiquement.
Signaler ce domaine Envoyez des éléments de preuve et contribuez à protéger les autres

Analyse VirusTotal

3 / Les fournisseurs de sécurité 91 ont signalé ce domaine
View on VT
Last analyzed First positive detection Previous stored snapshot: 0 detections
CRDF
Gridinsoft
SOCRadar
Données factuelles et rapports externesIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
If credentials were compromised, report immediately. Do not engage with recovery scammers.

Si vous avez saisi des informations d'identification de compte, des informations personnelles ou de paiement, ou téléchargé un fichier à partir de ce domaine, agissez immédiatement. Vous trouverez ci-dessous des ressources pour vous aider à signaler l'incident et à vous protéger.

Europol
Trouvez le canal de signalement officiel pour votre pays de l'UE
National police directory
Méfiez-vous des escrocs qui prétendent vous aider à récupérer vos biens ! Les criminels peuvent recontacter leurs victimes tout en se faisant passer pour des enquêteurs, des avocats ou des agents de recouvrement. Ne payez pas de frais initiaux et ne partagez pas vos informations d'identification. En savoir plus sur la fraude liée aux aides à la reprise →

Signalez-le à vos autorités locales

Sélectionnez votre pays pour obtenir contacts officiels en matière de cybercriminalité ou créer un projet de plainte →.

Annuaire de 97 pays
Brouillon assisté par l'IA : les détails de l'incident sont traités par le fournisseur d'IA Examinez-le et soumettez-le vous-même
Intégrer ce rapportRead-only HTML widget
HTML · IFRAME

Intégrer ce rapport

Partagez ces informations sur les menaces sur votre site web ou votre blog

embed.html
<iframe
  src="https://phishdestroy.io/fr/embed/domain/firstcallcover.com"
  title="PhishDestroy threat report for firstcallcover.com"
  width="100%" height="320"
  loading="lazy"
  referrerpolicy="no-referrer"
  sandbox="allow-same-origin allow-popups allow-popups-to-escape-sandbox"
  style="border:0;border-radius:12px;max-width:100%"
></iframe>

Une lettre de remerciement très sincère

Générateur de brouillon satirique

Destinataire
Contexte des frais

Brouillon satirique. Les montants des frais sont des estimations ; aucune attribution exacte à ce domaine n’est affirmée.