itrusrtcapiatlogin[.]webflow[.]io
“404 - Page not found”
itrusrtcapiatlogin.webflow.io — Contenu indisponible. Type d'arnaque : Credential Phishing. Résumé des preuves: VirusTotal 13/95 (ADMINUSLabs, alphaMountain.ai, BitDefender, CyRadar, ESET); CF Radar malicious; PhishDestroy score 89/100. Bureau d’enregistrement: MarkMonitor.
L’analyse détaillée de PhishDestroy AI reste en anglais afin de préserver le relevé forensique original.
The domain itrusrtcapiatlogin.webflow.io is currently offline, returning HTTP 404. It is hosted behind Cloudflare, utilizes HTTP/3, and serves a TLS certificate issued by Google Trust Services under the WE1 root. The authoritative nameservers are journey.ns.cloudflare.com and lamar.ns.cloudflare.com, and the domain resolves to the IPv6 address 2606:4700:440c::ac40:9708, which belongs to AS13335 Cloudflare, Inc., located in the United States. Registration records show the domain was created on May 08, 2013 and was purchased through MarkMonitor, Inc. VirusTotal analysis indicates that 13 of 95 scanned security vendors flagged the domain, and it appears on at least one public blocklist, where it was also blocked by the PhishDestroy service.
The intelligence categorizes the site as a credential phishing operation, and the risk level has been assigned as elevated. The page title returned by the server is “404 - Page not found”, providing no further content for analysis. Because the site is offline, no active phishing landing page can be examined, and the specific brand or service being spoofed remains unknown. Defenders should continue to block the domain at network perimeter and update URL filtering rules.
Monitoring of related C2 infrastructure or similar subdomains hosted on the same Cloudflare IP range is advised, as the attacker may reactivate the site or shift operations to a new host. Additional investigation should focus on any historic traffic logs that reference the domain, and on correlating the 13 vendor detections for clues about the underlying phishing kit. Until the site is confirmed inactive, maintain the elevated risk posture and ensure user education about unsolicited login requests that could be linked to this domain.
Renseignements sur la sécurité réseau
Processus de réponse aux menaces Pipeline
Statut de la liste de blocage publique
Technologies · 2 identified
Web infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
Analyse VirusTotal
Preuves archivées
Analyse des performances du site
Google PageSpeed Insights — mobile performance audit of itrusrtcapiatlogin.webflow.io · checked Mar 2, 2026
Données factuelles et rapports externes
Ce site vous a-t-il affecté ?
Si vous avez saisi des informations d'identification de compte, des informations personnelles ou de paiement, ou téléchargé un fichier à partir de ce domaine, agissez immédiatement. Vous trouverez ci-dessous des ressources pour vous aider à signaler l'incident et à vous protéger.
Signalez-le à vos autorités locales
Sélectionnez votre pays pour obtenir contacts officiels en matière de cybercriminalité ou créer un projet de plainte →.
Vérifier n'importe quel domaine
Analyse des menaces à l'aide de listes de blocage stockées, de WHOIS, de DNS et de preuves d'analyse publique
Scanner maintenantSignaler une tentative d'hameçonnage
Signalez les domaines suspects à notre base de données des menaces — protégez la communauté
SignalerFlux d'alertes en temps réel
Rapports de phishing récents et changements de disponibilité observés
SurveillerRestez informés, restez en sécurité
Surveillez les menaces en temps réel ou signalez cette alerte si vous pensez qu'il s'agit d'un faux positif