ct201209-wordpress-c4kau[.]tw1[.]ru
“Домен припаркован в Timeweb”
ct201209-wordpress-c4kau.tw1.ru — असत्यापित. ब्रांड प्रतिरूपण: Wordpress; घोटाले का प्रकार: Brand Impersonation. साक्ष्य सारांश: VirusTotal 12/91 (ADMINUSLabs, alphaMountain.ai, BitDefender, Chong Lua Dao, ESET); Google Safe Browsing flagged; CF Radar malicious; PhishDestroy score 91/100. रजिस्ट्रार: TW-Cloud (ASN: 9123).
मूल फॉरेंसिक रिकॉर्ड सुरक्षित रखने के लिए नीचे का विस्तृत PhishDestroy AI विश्लेषण अंग्रेज़ी में रखा गया है।
The domain ct201209-wordpress-c4kau.tw1.ru is currently active and hosted on IP 92.53.96.105, which resolves to a server in Russia operated by JSC TIMEWEB (ASN 9123). The domain was registered through TW-Cloud and uses Timeweb’s name servers (ns1.timeweb.ru, ns2.timeweb.ru, ns3.timeweb.org, ns4.timeweb.org). TLS negotiation presents a GlobalSign nv‑sa certificate issued by GlobalSign GCC R3 DV TLS CA 2020, indicating a valid SSL chain but offering no indication of legitimate ownership. HTTP requests receive a 302 redirect and the page title reports “Домен припаркован в Timeweb”, a generic parked‑domain notice, with no content related to WordPress. Google Safe Browsing classifies the site under the SOCIAL_ENGINEERING category, and VirusTotal records 13 of 95 security vendors flagging the domain as malicious. Independent trust scores are extremely low (Gridinsoft 0/100, Scamadviser 1/100). The domain appears on two public blocklists (PhishDestroy, PhishingDB) and is labeled as an impersonation of the WordPress brand. While the exact payload or credential‑harvesting mechanism has not been observed, the combination of a parked page, high‑risk classification, and multiple detections suggests the domain is being used to lure WordPress users or to host malicious content. Defenders should block network traffic to 92.53.96.105, add the domain to URL filtering policies, and monitor for any related DNS queries. Continuous re‑evaluation is advised, as the site may evolve to serve active phishing pages or malware.
सुरक्षा संकेत
नेटवर्क सुरक्षा इंटेलिजेंस
धमकी प्रतिक्रिया पाइपलाइन
सार्वजनिक ब्लॉकलिस्ट स्थिति
वायरसटोटल विश्लेषण
संग्रहीत साक्ष्य
साक्ष्य और बाहरी रिपोर्टें
क्या आप इस साइट से प्रभावित हुए?
यदि आपने खाता क्रेडेंशियल, व्यक्तिगत या भुगतान जानकारी दर्ज की है, या इस डोमेन से कोई फ़ाइल डाउनलोड की है, तो तुरंत कार्रवाई करें। घटना की रिपोर्ट करने और अपनी सुरक्षा करने में आपकी सहायता के लिए नीचे संसाधन दिए गए हैं।
अपने स्थानीय अधिकारियों को रिपोर्ट करें
आधिकारिक साइबर अपराध संपर्क, या एक शिकायत ड्राफ्ट बनाएं → प्राप्त करने के लिए अपना देश चुनें।
किसी भी डोमेन की जाँच करें
संग्रहीत ब्लॉकलिस्ट, WHOIS, DNS और सार्वजनिक स्कैन साक्ष्य का उपयोग करके खतरे का विश्लेषण
अभी स्कैन करेंफ़िशिंग की रिपोर्ट करें
संदिग्ध डोमेन हमारे थ्रेट डेटाबेस में जमा करें — समुदाय की सुरक्षा करें
रिपोर्ट करेंसीधा खतरा फीड
हाल की फ़िशिंग रिपोर्टें और उपलब्धता में परिवर्तन देखे गए
निगरानी करेंजानकारी में रहें, सुरक्षित रहें
लाइव खतरों की निगरानी करें या यदि आपको लगता है कि यह एक गलत सकारात्मक है तो इस लिस्टिंग को चुनौती दें।