ww[.]helpcenter-checkpoint-057353435646[.]fwh[.]is
“Webcake | Chưa xuất bản”
ww.helpcenter-checkpoint-057353435646.fwh.is — Contenu indisponible. Résumé des preuves: VirusTotal 9/91 (BitDefender, Cluster25, CRDF, Fortinet, G-Data); Spamhaus DBL_ABUSED_PHISH; CF Radar malicious; PhishDestroy score 78/100. Bureau d’enregistrement: FreeWebHostingArea.
L’analyse détaillée de PhishDestroy AI reste en anglais afin de préserver le relevé forensique original.
Analysis indicates that ww.helpcenter-checkpoint-057353435646.fwh.is is actively used for a generic phishing campaign. The domain was registered on 1 November 2024 and resolves to the IPv4 address 113.20.119.30. Hosting is provided through the Byet hosting network, as evidenced by the four Byet‑owned nameservers (ns1.byet.org through ns4.byet.org). The infrastructure has been listed on at least two public blocklists and is currently blocked by the PhishDestroy and OpenPhish feeds, confirming its malicious reputation.
VirusTotal scans show that nine of ninety‑one antivirus or URL‑reputation engines flag the domain, reinforcing the detection consensus. No public page title or SSL certificate details were supplied, and the content of the landing page has not been disclosed, leaving the exact visual lure uncertain. However, the classification as generic phishing is supported by the blocklist entries and the detection count. The domain remains active as of the report date (5 August 2026), indicating continued operation.
Defenders should add 113.20.119.30 and the full domain name to network‑level deny lists, update proxy and DNS filtering policies, and monitor for any outbound connections to the identified nameservers. Continuous re‑scanning with VirusTotal or similar multi‑engine services is recommended to capture any changes in detection scores. Organizations using email or web gateways should ensure that the domain is included in phishing‑specific block rules to prevent credential harvesting attempts.
Renseignements sur la sécurité réseau
Processus de réponse aux menaces Pipeline
Statut de la liste de blocage publique
Technologies · 2 identified
Nginx is a web server that can also be used as a reverse proxy, load balancer, mail proxy and HTTP cache.
nginx.org Confiance à 100 %OpenResty is a web platform based on nginx which can run Lua scripts using its LuaJIT engine.
openresty.org Confiance à 100 %Analyse VirusTotal
Preuves archivées
Analyse des performances du site
Google PageSpeed Insights — mobile performance audit of ww.helpcenter-checkpoint-057353435646.fwh.is · checked Aug 5, 2026
Données factuelles et rapports externes
Ce site vous a-t-il affecté ?
Si vous avez saisi des informations d'identification de compte, des informations personnelles ou de paiement, ou téléchargé un fichier à partir de ce domaine, agissez immédiatement. Vous trouverez ci-dessous des ressources pour vous aider à signaler l'incident et à vous protéger.
Signalez-le à vos autorités locales
Sélectionnez votre pays pour obtenir contacts officiels en matière de cybercriminalité ou créer un projet de plainte →.
Vérifier n'importe quel domaine
Analyse des menaces à l'aide de listes de blocage stockées, de WHOIS, de DNS et de preuves d'analyse publique
Scanner maintenantSignaler une tentative d'hameçonnage
Signalez les domaines suspects à notre base de données des menaces — protégez la communauté
SignalerFlux d'alertes en temps réel
Rapports de phishing récents et changements de disponibilité observés
SurveillerRestez informés, restez en sécurité
Surveillez les menaces en temps réel ou signalez cette alerte si vous pensez qu'il s'agit d'un faux positif