lvsclinic[.]ir
“Index of /”
lvsclinic.ir — Non vérifié. Type d'arnaque : Credential Phishing. Résumé des preuves: VirusTotal 15/91 (ADMINUSLabs, alphaMountain.ai, BitDefender, CRDF, CyRadar); Spamhaus DBL_PHISH; PhishDestroy score 98/100.
L’analyse détaillée de PhishDestroy AI reste en anglais afin de préserver le relevé forensique original.
This domain, lvsclinic.ir, was identified as a credential theft operation targeting users of medical or clinic-related services. Analysis indicates the infrastructure was designed to harvest login credentials by impersonating legitimate healthcare portals, a common tactic in targeted phishing campaigns. The domain’s design and content likely included fake login forms or patient portals to deceive victims into submitting sensitive information, such as usernames, passwords, or personal health data. Infrastructure analysis reveals the domain resolved to the IP address 87.107.10.74, hosted under AS208161 (Pars Shabakeh Azarakhsh LLC) in Iran. The domain lacked an SSL certificate, increasing the risk of interception or tampering during data transmission. It was flagged by 17 out of 95 security vendors on VirusTotal and appeared on two security blocklists, including PhishDestroy and PhishingDB. The page title, 'Index of /,' suggests an exposed directory listing, which may have been exploited to host malicious content or redirect users to credential harvesting pages. Users who visited lvsclinic.ir or interacted with its content should take immediate action to mitigate potential risks. First, reset any credentials entered on the site, particularly for medical or financial accounts. Monitor accounts for unauthorized activity, such as logins from unfamiliar locations or changes to personal information. If the domain was accessed via a corporate or institutional network, report the incident to the organization’s security team for further investigation. Additionally, scan the device used to access the domain for malware or unauthorized software, as phishing sites often deploy secondary payloads to maintain persistence or exfiltrate data.
Renseignements sur la sécurité réseau
Processus de réponse aux menaces Pipeline
Statut de la liste de blocage publique
Analyse VirusTotal
Preuves archivées
Données factuelles et rapports externes
Ce site vous a-t-il affecté ?
Si vous avez saisi des informations d'identification de compte, des informations personnelles ou de paiement, ou téléchargé un fichier à partir de ce domaine, agissez immédiatement. Vous trouverez ci-dessous des ressources pour vous aider à signaler l'incident et à vous protéger.
Signalez-le à vos autorités locales
Sélectionnez votre pays pour obtenir contacts officiels en matière de cybercriminalité ou créer un projet de plainte →.
Vérifier n'importe quel domaine
Analyse des menaces à l'aide de listes de blocage stockées, de WHOIS, de DNS et de preuves d'analyse publique
Scanner maintenantSignaler une tentative d'hameçonnage
Signalez les domaines suspects à notre base de données des menaces — protégez la communauté
SignalerFlux d'alertes en temps réel
Rapports de phishing récents et changements de disponibilité observés
SurveillerRestez informés, restez en sécurité
Surveillez les menaces en temps réel ou signalez cette alerte si vous pensez qu'il s'agit d'un faux positif