url-link[.]cc
“URL Shortener”
Résumé des preuves
Analysis of the domain url-link.cc indicates it was actively involved in phishing operations as of July 2026. The domain, registered on March 6, 2026, through NiceNIC International Group Co., Limited, presented itself as a URL shortener service, as evidenced by its page title 'URL Shortener.' This aligns with common phishing tactics where legitimate-looking services are used to obfuscate malicious links. The domain resolved to the IP address 151.247.193.142, hosted under AS399486 (12651980 CANADA INC.), with geolocation data pointing to France. Infrastructure analysis reveals the domain utilized nameservers ns1.eggywall.cc and ns2.eggywall.cc, which may suggest a broader malicious infrastructure or shared hosting environment among threat actors.
Detection data from July 24, 2026, shows that 13 out of 95 security vendors on VirusTotal flagged url-link.cc as malicious, a detection rate consistent with confirmed phishing domains. Additionally, the domain appeared on one security blocklist and was blocked by PhishDestroy, further corroborating its classification as a phishing threat. Notably, the domain lacked an SSL certificate, a red flag for user security and a common characteristic of low-effort phishing sites. At the time of reporting, url-link.cc was offline, though its prior activity and detection history warrant continued monitoring.
Defenders should treat this domain as a confirmed phishing vector, particularly given its use of URL shortening as a social engineering tactic. Network-level blocks at the IP and domain level are recommended, along with monitoring for any re-registration or DNS changes. While the exact target or brand impersonated by this campaign remains unconfirmed due to limited page content analysis, the infrastructure and detection patterns strongly suggest its use in distributing phishing links. Further investigation into the nameserver infrastructure (eggywall.cc) may uncover additional related threats.
Instantané des preuves transmises
- Envoyé
- Entrées du registre
- 1
- ID du dossier
PD-20260306-45966A- Titre de la page capturée
- URL Shortener
- Artefact PDF
- Preuve PDF
Texte intégral des preuves
Policy Violations: “Services may be used only for lawful purposes… fraud, abuse and illegal activity prohibited. Violations may result in immediate suspension.” + dedicated abuse handling and takedown
Applicable Laws: Crimes Ordinance Cap.200 (Fraud), Theft Ordinance Cap.210 §16A (fraud by deception), Personal Data (Privacy) Ordinance Cap.486
Data Coverage
Renseignements sur la sécurité réseau
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Hagezi Threat Feed | url-link.cc |
malicious | Sinkholed |
| DNS4EU | url-link.cc |
malicious | Sinkholed |
Processus de réponse aux menaces Pipeline
Couverture des listes de blocage
10 sources externes surveillées · instantané du 10/08/2026
10 sources externes surveillées Aucune correspondance
Chronologie de détection
-
VirusTotal
0 → 16
-
Cloudflare Radar
Analyse Cloudflare Radar enregistrée · Ouvrir l’analyse
Analyse VirusTotal
Ce site vous a-t-il affecté ?
Si vous avez saisi des informations d'identification de compte, des informations personnelles ou de paiement, ou téléchargé un fichier à partir de ce domaine, agissez immédiatement. Vous trouverez ci-dessous des ressources pour vous aider à signaler l'incident et à vous protéger.
Signalez-le à vos autorités locales
Sélectionnez votre pays pour obtenir contacts officiels en matière de cybercriminalité ou créer un projet de plainte →.
Vérifier n'importe quel domaine
Analyse des menaces à l'aide de listes de blocage stockées, de WHOIS, de DNS et de preuves d'analyse publique
Scanner maintenantSignaler une tentative d'hameçonnage
Signalez les domaines suspects à notre base de données des menaces — protégez la communauté
SignalerFlux d'alertes en temps réel
Rapports de phishing récents et changements de disponibilité observés
SurveillerRestez informés, restez en sécurité
Surveillez les menaces en temps réel ou signalez cette alerte si vous pensez qu'il s'agit d'un faux positif