cyrtoprimefx[.]live
“Home - The Wealth Press”
cyrtoprimefx.live — Belum terverifikasi. Peniruan identitas merek: Across; Jenis penipuan: Brand Impersonation. Ringkasan bukti: VirusTotal 5/91 (alphaMountain.ai, Chong Lua Dao, CRDF, Fortinet, Gridinsoft); PhishDestroy score 65/100. Registrar: OwnRegistrar.
Analisis terperinci PhishDestroy AI di bawah tetap berbahasa Inggris untuk menjaga catatan forensik asli.
The domain cyrtoprimefx.live was registered on September 03, 2025 and is currently taken offline, yet it remains flagged by multiple security controls. Infrastructure analysis shows it resolves to the IPv4 address 78.46.40.242, which is hosted in Germany under AS24940 operated by Hetzner Online GmbH. No TLS certificate is presented for the site, indicating that any traffic would have been unencrypted. The page title returned from the HTTP response is "Home - The Wealth Press," which does not correspond to the advertised brand target listed as "across," confirming a mismatch between the site content and the claimed impersonation scope.
The domain has a Gridinsoft trust score of 0 out of 100, reflecting a very poor reputation, and it is listed on a single security blocklist. Detection engines on VirusTotal reported three positive detections out of ninety‑five scanners, and the domain is specifically blocked by the PhishDestroy service. These signals collectively point to a brand‑impersonation campaign that attempted to lure victims under the guise of a legitimate brand. Uncertainty remains regarding the exact phishing kit or the full extent of victim outreach, as no further forensic artifacts such as login pages or payloads have been disclosed.
Defenders should ensure that the IP address 78.46.40.242 is added to outbound and inbound firewall deny lists, enforce domain‑level blocking for cyrtoprimefx.live across web filtering solutions, and monitor Hetzner‑hosted ranges for any re‑registration of similar domains. Continuous telemetry collection from DNS resolvers and endpoint security agents is recommended to detect any resurgence of the domain or associated infrastructure. Given the elevated risk rating, security teams should also update internal threat intelligence repositories with the observed indicators of compromise and disseminate the findings to incident response personnel for rapid containment if related activity surfaces.
Alur Tanggapan Ancaman Pipeline
Status Daftar Blokir Publik
Tangkapan tersimpan
Intelijen Domain
Rincian teknisDNS, SAN SSL, cap waktu
ICANN OVERSIGHT
Akreditasi dan konteks RAA
Akreditasi dan konteks RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Analisis VirusTotal
Bukti & Laporan Eksternal
Apakah Anda Terpengaruh oleh Situs Ini?
Jika Anda memasukkan kredensial akun, informasi pribadi atau pembayaran, atau mengunduh file dari domain ini, segera ambil tindakan. Di bawah ini adalah sumber daya untuk membantu Anda melaporkan insiden tersebut dan melindungi diri Anda sendiri.
Laporkan kepada Pihak Berwenang di Daerah Anda
Pilih negara Anda untuk mendapatkan kontak resmi kejahatan dunia maya, atau membuat draf pengaduan →.
Periksa Domain Apa Pun
Analisis ancaman menggunakan daftar blokir yang disimpan, WHOIS, DNS, dan bukti pemindaian publik
Pindai SekarangLaporkan Phishing
Laporkan domain yang mencurigakan ke basis data ancaman kami — lindungi komunitas
LaporanPemberitahuan Ancaman Real-Time
Laporan phishing terbaru dan perubahan ketersediaan yang diamati
PantauTetap Terinformasi, Tetap Aman
Pantau ancaman secara langsung atau ajukan keberatan terhadap daftar ini jika Anda yakin ini merupakan false positive