financemoneycare.com.habithousecozy.com
“Finance Money Care”
financemoneycare.com.habithousecozy.com — Contenu indisponible. Usurpation de l'identité de la marque : Unknown; Type d'arnaque : Generic Phishing. Résumé des preuves: VirusTotal 6/91 (ADMINUSLabs, alphaMountain.ai, Forcepoint ThreatSeeker, Fortinet, Gridinsoft); URLQuery 1 alert; Spamhaus DBL_PHISH; PhishDestroy score 85/100. Bureau d’enregistrement: Dynadot.
L’analyse détaillée de PhishDestroy AI reste en anglais afin de préserver le relevé forensique original.
Résumé des preuves
This domain, financemoneycare.com.habithousecozy.com, is flagged as a high-risk credential phishing resource targeting users under the guise of a financial service portal. Analysis of the page title, 'Finance Money Care,' suggests an attempt to impersonate legitimate financial institutions or money management platforms, likely aiming to harvest login credentials, personal identification details, or financial account information. No specific drainer kit signatures have been confirmed at this stage, though the infrastructure aligns with common phishing toolkits used in credential theft campaigns. Infrastructure analysis reveals the domain was registered on February 25, 2026, through Dynadot Inc, a registrar frequently observed in phishing operations. It resolves to the IP address 194.36.191.196, hosted on AS60117 (Host Sailor Ltd) in the Netherlands. The domain is secured with a Let's Encrypt SSL certificate (R12), a tactic often employed to lend false legitimacy to malicious sites. Detection metrics indicate a VirusTotal score of 3/95, with only one security blocklist currently flagging the domain. No entries were found in Google Safe Browsing at the time of assessment, though this does not preclude malicious intent. The domain remains active and continues to host phishing content, posing a persistent risk to users who may encounter it through spam emails, compromised advertisements, or social engineering tactics. Response actions should include immediate blacklisting by network security providers, takedown requests to the hosting provider, and registrar-level suspension. Despite low detection counts, the domain's recent creation date, use of a high-reputation registrar, and targeted financial branding elevate its risk profile. Users are advised to avoid interaction, verify financial service URLs through official channels, and report suspicious links to relevant security teams for further mitigation.
Renseignements sur la sécurité réseau
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Cloudflare DNS | leostop.com |
malicious | Sinkholed |
Forensic History & Detection Timeline
-
Domain Status Transition Aug 9, 2026 · 00:15 UTCDomain state transitioned from dead to alive.
-
Domain Status Transition Aug 8, 2026 · 00:29 UTCDomain state transitioned from alive to dead.
Processus de réponse aux menaces Pipeline
Statut de la liste de blocage publique
Evasion analysis
Cloaking & traffic-distribution check
Stored crawler-versus-browser observations for this host, plus a live fingerprint check for Keitaro-style traffic distribution systems.
- Stored cloaking flag
- Not observed
- Score de dissimulation
- 0/6
- Last cloaking scan
Scanner note: dns_error: raw=dns_error; via=local_dns_prefilter
Technologies · 6 identified
Analyse VirusTotal
Données factuelles et rapports externes
Ce site vous a-t-il affecté ?
Si vous avez saisi des informations d'identification de compte, des informations personnelles ou de paiement, ou téléchargé un fichier à partir de ce domaine, agissez immédiatement. Vous trouverez ci-dessous des ressources pour vous aider à signaler l'incident et à vous protéger.
Signalez-le à vos autorités locales
Sélectionnez votre pays pour obtenir contacts officiels en matière de cybercriminalité ou créer un projet de plainte →.
Vérifier n'importe quel domaine
Analyse des menaces à l'aide de listes de blocage stockées, de WHOIS, de DNS et de preuves d'analyse publique
Scanner maintenantSignaler une tentative d'hameçonnage
Signalez les domaines suspects à notre base de données des menaces — protégez la communauté
SignalerFlux d'alertes en temps réel
Rapports de phishing récents et changements de disponibilité observés
SurveillerRestez informés, restez en sécurité
Surveillez les menaces en temps réel ou signalez cette alerte si vous pensez qu'il s'agit d'un faux positif