cs880817-wordpress-f5a04[.]tw1[.]ru
“Домен припаркован в Timeweb”
cs880817-wordpress-f5a04.tw1.ru — Belum terverifikasi. Peniruan identitas merek: Wordpress; Jenis penipuan: Brand Impersonation. Ringkasan bukti: VirusTotal 14/91 (ADMINUSLabs, alphaMountain.ai, BitDefender, CyRadar, ESET); Google Safe Browsing flagged; CF Radar malicious; PhishDestroy score 97/100. Registrar: TW-Cloud (ASN: 9123).
Analisis terperinci PhishDestroy AI di bawah tetap berbahasa Inggris untuk menjaga catatan forensik asli.
This domain, cs880817-wordpress-f5a04.tw1.ru, is actively flagged as a high-risk brand impersonation threat targeting WordPress. Analysis indicates the domain is registered through TW-Cloud (ASN 9123) and currently resolves to the IPv6 address 2a03:6f00:1::5c35:6069. The page title, 'Домен припаркован в Timeweb,' suggests it may be hosted on a parked domain service, though the exact content remains unanalyzed. Security vendors have detected malicious indicators, with 12 out of 95 engines on VirusTotal flagging the domain, and it appears on two security blocklists, including PhishDestroy and PhishingDB. The domain is explicitly categorized as engaging in social engineering, as confirmed by Google Safe Browsing. Its Gridinsoft trust score of 0/100 and Scamadviser trust score of 1/100 further corroborate its high-risk classification. The SSL certificate is issued by GlobalSign nv-sa, which does not mitigate the underlying threat but may lend a superficial appearance of legitimacy. No specific phishing kit or payload has been identified in the available data, leaving the exact attack vector uncertain. Defenders should treat this domain as an active threat. Immediate action includes blocking the domain and its resolving IP at the network perimeter, as well as monitoring for any internal connections to it. Given the domain's association with brand impersonation and social engineering, user awareness training may be warranted to prevent potential credential harvesting or malware distribution. The domain remains active as of July 12, 2026, and should be prioritized for further investigation if any internal systems have interacted with it. No evidence suggests this is part of a larger campaign, but its registration through a known hosting provider warrants scrutiny of related infrastructure.
Sinyal Keamanan
Intelijen Keamanan Jaringan
Alur Tanggapan Ancaman Pipeline
Status Daftar Blokir Publik
Analisis VirusTotal
Bukti Terarsip
Bukti & Laporan Eksternal
Apakah Anda Terpengaruh oleh Situs Ini?
Jika Anda memasukkan kredensial akun, informasi pribadi atau pembayaran, atau mengunduh file dari domain ini, segera ambil tindakan. Di bawah ini adalah sumber daya untuk membantu Anda melaporkan insiden tersebut dan melindungi diri Anda sendiri.
Laporkan kepada Pihak Berwenang di Daerah Anda
Pilih negara Anda untuk mendapatkan kontak resmi kejahatan dunia maya, atau membuat draf pengaduan →.
Periksa Domain Apa Pun
Analisis ancaman menggunakan daftar blokir yang disimpan, WHOIS, DNS, dan bukti pemindaian publik
Pindai SekarangLaporkan Phishing
Laporkan domain yang mencurigakan ke basis data ancaman kami — lindungi komunitas
LaporanPemberitahuan Ancaman Real-Time
Laporan phishing terbaru dan perubahan ketersediaan yang diamati
PantauTetap Terinformasi, Tetap Aman
Pantau ancaman secara langsung atau ajukan keberatan terhadap daftar ini jika Anda yakin ini merupakan false positive