ikhwancast[.]com
“Transatlantic Firm Dickinson | Law Bond Womble”
Résumé des preuves
The domain ikhwancast.com was observed for the first time on September 13, 2025 and is currently listed as active with an elevated risk rating. Registration records show it was created through Hosting Concepts B.V. operating under the Registrar.eu brand, indicating a commercial registrar based in the European Union. Network resolution points the domain to the IP address 172.67.220.238, which is hosted on a content delivery network commonly used for legitimate traffic, complicating attribution of the underlying server infrastructure. Malware and phishing detection services have flagged the domain; VirusTotal reports 18 of 91 scanned security vendors marking it as malicious, and it appears on a single external blocklist.
The domain is also blocked by the PhishDestroy feed, reinforcing the suspicion of phishing use. No public page title, SSL certificate details, or HTTP response codes have been published in the available intelligence, leaving the exact content and login collection mechanisms unverified. The limited blocklist presence (one listing) suggests early‑stage deployment, and the modest detection count (18/91) may reflect either a newly registered domain or evasion techniques that have not yet triggered broader signatures. Observers should also query passive DNS services for historical A records to detect any prior pointings that could reveal a shift in hosting.
Consequently, analysts should treat any email or web interaction referencing ikhwancast.com as potentially malicious, enforce block rules at the DNS and proxy layers, and monitor for additional indicators such as newly observed IP addresses or certificate changes. Continuous observation of the hosting provider’s abuse channels is recommended to gather further forensic artifacts, and any traffic directed to the resolved IP should be logged for correlation with credential harvesting attempts.
Data Coverage
Renseignements sur la sécurité réseau
Processus de réponse aux menaces Pipeline
Couverture des listes de blocage
10 sources externes surveillées · instantané du 11/08/2026
10 sources externes surveillées Aucune correspondance
Chronologie de détection
-
État du domaine
Accessible → Inaccessible
-
État du domaine
Inaccessible → Accessible
Informations sur les domaines
Détails techniquesDNS, noms TLS et horodatages
ICANN OVERSIGHT
Contexte de l’accréditation et du RAA
Contexte de l’accréditation et du RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Analyse VirusTotal
Ce site vous a-t-il affecté ?
Si vous avez saisi des informations d'identification de compte, des informations personnelles ou de paiement, ou téléchargé un fichier à partir de ce domaine, agissez immédiatement. Vous trouverez ci-dessous des ressources pour vous aider à signaler l'incident et à vous protéger.
Signalez-le à vos autorités locales
Sélectionnez votre pays pour obtenir contacts officiels en matière de cybercriminalité ou créer un projet de plainte →.
Vérifier n'importe quel domaine
Analyse des menaces à l'aide de listes de blocage stockées, de WHOIS, de DNS et de preuves d'analyse publique
Scanner maintenantSignaler une tentative d'hameçonnage
Signalez les domaines suspects à notre base de données des menaces — protégez la communauté
SignalerFlux d'alertes en temps réel
Rapports de phishing récents et changements de disponibilité observés
SurveillerRestez informés, restez en sécurité
Surveillez les menaces en temps réel ou signalez cette alerte si vous pensez qu'il s'agit d'un faux positif