mphengbona[.]co[.]za
“My Blog – My WordPress Blog”
mphengbona.co.za — Non vérifié. Type d'arnaque : Credential Phishing. Résumé des preuves: VirusTotal 16/93 (ADMINUSLabs, alphaMountain.ai, BitDefender, CRDF, CyRadar); PhishDestroy score 95/100. Bureau d’enregistrement: Domains.
L’analyse détaillée de PhishDestroy AI reste en anglais afin de préserver le relevé forensique original.
This domain, mphengbona.co.za, operates as a fake login portal designed to harvest user credentials. Analysis indicates the infrastructure mimics legitimate authentication pages, tricking visitors into entering sensitive information such as usernames, passwords, or multi-factor authentication codes. The site employs a 404 Not Found page as a cloaking mechanism, likely to evade automated detection while still capturing data from unsuspecting users who reach it through deceptive links or redirects. Infrastructure analysis reveals multiple red flags confirming its malicious nature. The domain was registered on February 21, 2026, through the registrar Domains, an unusually future-dated creation that may indicate an attempt to bypass reputation-based filters. Security vendors on VirusTotal flagged it as malicious, with 16 out of 95 engines detecting it as a phishing threat. Additionally, the domain resolves to the IP address 169.239.218.62, hosted on AS327979 (DIAMATRIX C.C) in South Africa, and appears on one security blocklist. The SSL certificate, issued by Let’s Encrypt (R13), provides minimal encryption, a common tactic to lend false legitimacy to phishing sites. If you visited mphengbona.co.za or entered credentials on a page resembling this domain, immediate action is required. First, revoke any active sessions on accounts that may have been exposed and change passwords using a secure device. Enable multi-factor authentication if not already active, and monitor linked accounts for unauthorized activity. Report the incident to your organization’s security team or a trusted incident response provider. Avoid reusing passwords across platforms, and consider scanning your device for malware, as phishing sites often deploy additional payloads. If financial or sensitive data was submitted, contact relevant institutions to flag potential fraud.
Processus de réponse aux menaces Pipeline
Statut de la liste de blocage publique
Technologies · 2 identified
HTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org Confiance à 100 %Analyse VirusTotal
Preuves archivées
Analyse de la configuration du site
Données factuelles et rapports externes
Ce site vous a-t-il affecté ?
Si vous avez saisi des informations d'identification de compte, des informations personnelles ou de paiement, ou téléchargé un fichier à partir de ce domaine, agissez immédiatement. Vous trouverez ci-dessous des ressources pour vous aider à signaler l'incident et à vous protéger.
Signalez-le à vos autorités locales
Sélectionnez votre pays pour obtenir contacts officiels en matière de cybercriminalité ou créer un projet de plainte →.
Vérifier n'importe quel domaine
Analyse des menaces à l'aide de listes de blocage stockées, de WHOIS, de DNS et de preuves d'analyse publique
Scanner maintenantSignaler une tentative d'hameçonnage
Signalez les domaines suspects à notre base de données des menaces — protégez la communauté
SignalerFlux d'alertes en temps réel
Rapports de phishing récents et changements de disponibilité observés
SurveillerRestez informés, restez en sécurité
Surveillez les menaces en temps réel ou signalez cette alerte si vous pensez qu'il s'agit d'un faux positif