auth2usngwd0c88bdrvsharepoint[.]wardhealthpa[.]com
“Processing...”
auth2usngwd0c88bdrvsharepoint.wardhealthpa.com — Ammantato · raggiungibile. Tipo di truffa: Generic Phishing. Riepilogo delle prove: VirusTotal 18/91 (ADMINUSLabs, Criminal IP, BitDefender, Chong Lua Dao, Cluster25); CF Radar malicious; cloaking observed; PhishDestroy score 95/100. Registrar: Wild West Domains.
L’analisi dettagliata di PhishDestroy AI resta in inglese per preservare il rapporto forense originale.
The domain auth2usngwd0c88bdrvsharepoint.wardhealthpa.com is currently active and confirmed as a fraudulent SharePoint login portal designed to harvest credentials. Analysis indicates this is a targeted brand impersonation attack, mimicking legitimate Microsoft SharePoint authentication pages to deceive users into submitting corporate or personal login details. The site remains operational, displaying a generic 'Processing...' page title, which is commonly used to mask malicious intent while backend scripts capture submitted data. Infrastructure analysis reveals multiple high-risk indicators. The domain was registered on June 03, 2026, through Wild West Domains, LLC, a registrar frequently associated with newly created phishing domains. It resolves to the IP address 172.86.91.9 and is flagged by 21 of 95 security vendors on VirusTotal, including detection as a generic phishing threat. Additionally, the domain appears on one security blocklist and is actively blocked by enterprise phishing detection systems. The SSL certificate is issued by Let's Encrypt (YE1), a common choice for threat actors due to its low-cost and automated issuance process. Current status confirms the domain remains active and operational. Organizations and users are advised to block the domain and its associated IP at the network perimeter. Security teams should review logs for connections to 172.86.91.9 and monitor for credential submission attempts originating from internal networks. If user interaction is suspected, immediate password resets and multi-factor authentication enforcement are recommended. Proactive measures include updating endpoint protection rules to detect and prevent access to newly registered domains with similar naming patterns.
Informazioni sulla sicurezza di rete
Pipeline di risposta alle minacce
Stato della lista di blocco pubblica
Analisi dei domini
Dettagli tecniciDNS, SAN SSL, timestamp
ICANN OVERSIGHT
Registration: wardhealthpa.com
Accreditamento e contesto RAA
Accreditamento e contesto RAA
Registrar accreditation and DNS abuse obligations
For the registrable domain wardhealthpa.com behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Tecnologie · 3 identified
Ubuntu is a free and open-source operating system on Linux for the enterprise server, desktop, cloud, and IoT.
www.ubuntu.com Confidenza al 100%Apache is a free and open-source cross-platform web server software.
httpd.apache.org Confidenza al 100%HTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org Confidenza al 100%Analisi di VirusTotal
Dati e relazioni esterne
Questo sito ti ha influenzato in qualche modo?
Se hai inserito credenziali dell'account, informazioni personali o di pagamento oppure hai scaricato un file da questo dominio, agisci immediatamente. Di seguito sono riportate le risorse per aiutarti a segnalare l'incidente e proteggerti.
Segnalalo alle autorità locali
Seleziona il tuo Paese per ottenere contatti ufficiali del crimine informatico o creare una bozza di reclamo →.
Verifica qualsiasi dominio
Analisi delle minacce utilizzando blocklist archiviate, WHOIS, DNS e prove di scansione pubblica
Scansiona oraSegnala un tentativo di phishing
Segnala i domini sospetti al nostro database delle minacce — proteggi la comunità
SegnalaFeed in tempo reale sulle minacce
Segnalazioni recenti di phishing e modifiche osservate della disponibilità
MonitoraRimani informato, rimani al sicuro
Controlla le minacce in tempo reale oppure contesta questa segnalazione se ritieni che si tratti di un falso positivo