cj106932-wordpress-urg2s[.]tw1[.]ru
“WordPress”
cj106932-wordpress-urg2s.tw1.ru — असत्यापित. ब्रांड प्रतिरूपण: Wordpress; घोटाले का प्रकार: Brand Impersonation. साक्ष्य सारांश: VirusTotal 12/91 (alphaMountain.ai, BitDefender, Chong Lua Dao, CyRadar, ESET); Google Safe Browsing flagged; PhishDestroy score 98/100. रजिस्ट्रार: TW-Cloud (ASN: 9123).
मूल फॉरेंसिक रिकॉर्ड सुरक्षित रखने के लिए नीचे का विस्तृत PhishDestroy AI विश्लेषण अंग्रेज़ी में रखा गया है।
This domain, cj106932-wordpress-urg2s.tw1.ru, is currently active and hosts a brand‑impersonation campaign targeting WordPress. Infrastructure analysis reveals that the domain resolves to IP 92.53.96.105, which belongs to ASN 9123 (JSC TIMEWEB) and is geolocated in Russia. The domain was registered through the TW‑Cloud registrar, and its authoritative name servers are ns1.timeweb.ru, ns2.timeweb.ru, ns3.timeweb.org, and ns4.timeweb.org. TLS termination is provided by a GlobalSign nv‑sa certificate chained to the GlobalSign GCC R3 DV TLS CA 2020, indicating a valid‑looking HTTPS service. An HTTP request to the site returns a 302 redirect, and the page title reported by scanners is “WordPress”, matching the declared brand target.
Reputation services have listed the domain on two blocklists, specifically PhishDestroy and PhishingDB, and Google Safe Browsing flags it for SOCIAL_ENGINEERING. VirusTotal scans show that 13 out of 95 security vendors have flagged the domain as malicious. The Gridinsoft trust score is 0 / 100, reinforcing the classification as high‑risk. The overall risk level is marked as high, and the campaign status remains active.
Analysis indicates that the observable indicators—IP address, ASN, SSL certificate, redirect behavior, and multiple vendor detections—strongly support the presence of a WordPress brand‑impersonation operation. No public content analysis is available, so the exact phishing page structure and credential‑harvesting mechanisms remain unknown. Defenders should block the domain and its resolving IP at network perimeter devices, update URL filtering lists with the identified blocklist entries, and monitor for any traffic to the associated nameservers. Continuous re‑evaluation is advised, as additional detections may emerge from further sandbox or endpoint analysis.
धमकी प्रतिक्रिया पाइपलाइन
सार्वजनिक ब्लॉकलिस्ट स्थिति
वायरसटोटल विश्लेषण
संग्रहीत साक्ष्य
साक्ष्य और बाहरी रिपोर्टें
क्या आप इस साइट से प्रभावित हुए?
यदि आपने खाता क्रेडेंशियल, व्यक्तिगत या भुगतान जानकारी दर्ज की है, या इस डोमेन से कोई फ़ाइल डाउनलोड की है, तो तुरंत कार्रवाई करें। घटना की रिपोर्ट करने और अपनी सुरक्षा करने में आपकी सहायता के लिए नीचे संसाधन दिए गए हैं।
अपने स्थानीय अधिकारियों को रिपोर्ट करें
आधिकारिक साइबर अपराध संपर्क, या एक शिकायत ड्राफ्ट बनाएं → प्राप्त करने के लिए अपना देश चुनें।
किसी भी डोमेन की जाँच करें
संग्रहीत ब्लॉकलिस्ट, WHOIS, DNS और सार्वजनिक स्कैन साक्ष्य का उपयोग करके खतरे का विश्लेषण
अभी स्कैन करेंफ़िशिंग की रिपोर्ट करें
संदिग्ध डोमेन हमारे थ्रेट डेटाबेस में जमा करें — समुदाय की सुरक्षा करें
रिपोर्ट करेंसीधा खतरा फीड
हाल की फ़िशिंग रिपोर्टें और उपलब्धता में परिवर्तन देखे गए
निगरानी करेंजानकारी में रहें, सुरक्षित रहें
लाइव खतरों की निगरानी करें या यदि आपको लगता है कि यह एक गलत सकारात्मक है तो इस लिस्टिंग को चुनौती दें।