wolrdlibartyfinancials[.]xyz
“Nur einen Moment…”
wolrdlibartyfinancials.xyz — Contenu indisponible (HTTP 502). Résumé des preuves: VirusTotal 5/93 (ChainPatrol, alphaMountain.ai, CyRadar, Forcepoint ThreatSeeker, Seclookup); PhishDestroy score 65/100.
L’analyse détaillée de PhishDestroy AI reste en anglais afin de préserver le relevé forensique original.
Analysis indicates that the domain wolrdlibartyfinancials.xyz was registered on 21 February 2026 and resolves to the IP address 188.114.96.3, which is hosted by Cloudflare (AS13335) in the United States. The site presented the HTML title “Nur einen Moment…”, a phrase commonly used on placeholder or waiting pages, but no further content has been captured because the host is currently offline. The domain appears on a single security blocklist and has been flagged by PhishDestroy, confirming that it has been identified as a phishing‑related resource. VirusTotal scans show that five of ninety‑three antivirus engines returned a positive detection, indicating that a minority of scanners recognise malicious behavior associated with the domain.
The SSL certificate is listed as “WE1”, suggesting a generic or potentially self‑signed certificate, which does not provide additional trust. Because the site is no longer reachable, active payload collection is not possible, but the historical evidence points to a generic phishing campaign that likely attempts to lure victims with a waiting‑page tactic. Defenders should add the domain and its associated IP address to block lists, monitor for any future DNS resolution changes, and enforce outbound filtering to prevent connections to Cloudflare‑hosted IPs that have been previously abused.
Continuous re‑scanning on VirusTotal and inclusion in URL filtering solutions are recommended to capture any re‑activation. At present, the primary uncertainty is the exact phishing target or credential‑capture mechanism, as no brand or login form details have been observed. Organizations should remain vigilant for emails or messages that reference the domain or similar German‑language prompts, and should educate users to disregard unexpected “just a moment” redirects.
Processus de réponse aux menaces Pipeline
Statut de la liste de blocage publique
Analyse VirusTotal
Données factuelles et rapports externes
Ce site vous a-t-il affecté ?
Si vous avez saisi des informations d'identification de compte, des informations personnelles ou de paiement, ou téléchargé un fichier à partir de ce domaine, agissez immédiatement. Vous trouverez ci-dessous des ressources pour vous aider à signaler l'incident et à vous protéger.
Signalez-le à vos autorités locales
Sélectionnez votre pays pour obtenir contacts officiels en matière de cybercriminalité ou créer un projet de plainte →.
Vérifier n'importe quel domaine
Analyse des menaces à l'aide de listes de blocage stockées, de WHOIS, de DNS et de preuves d'analyse publique
Scanner maintenantSignaler une tentative d'hameçonnage
Signalez les domaines suspects à notre base de données des menaces — protégez la communauté
SignalerFlux d'alertes en temps réel
Rapports de phishing récents et changements de disponibilité observés
SurveillerRestez informés, restez en sécurité
Surveillez les menaces en temps réel ou signalez cette alerte si vous pensez qu'il s'agit d'un faux positif