MALICIOUS — CRITICAL
encryptedporfoliodocuments[.]replit[.]app
The domain encryptedporfoliodocuments.replit.app is currently classified as a credential phishing site and remains active as of the report date, July 22, 2026.
- VirusTotal
- 11/91
- Blocklists
- No stored match
- Disponibilità
- Ultimo attivo conosciuto · HTTP 200
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
encryptedporfoliodocuments.replit.app — Ultimo attivo conosciuto (HTTP 200). Simulazione del marchio: Adobe; Tipo di truffa: Credential Phishing. Riepilogo delle prove: VirusTotal 11/91 (ADMINUSLabs, alphaMountain.ai, BitDefender, CRDF, ESET); URLScan malicious verdict; PhishDestroy score 93/100. Registrar: Replit.
L’analisi dettagliata di PhishDestroy AI resta in inglese per preservare il rapporto forense originale.
Evidence Analysis
The domain encryptedporfoliodocuments.replit.app is currently classified as a credential phishing site and remains active as of the report date, July 22, 2026. Infrastructure analysis shows the domain resolves to the IPv4 address 34.117.33.233, which is allocated to Google LLC under ASN 396982 and geolocated in the United States. The hosting provider is Replit, as indicated by the registrar information. An SSL certificate issued by Google Trust Services (CN=WR3) is present, confirming that Transport Layer Security is employed, but the certificate does not mitigate the malicious intent.
HTTP response code 200 is returned, and the only observed page title is "Please wait," suggesting a possible redirect or loading stage. Detection engines on VirusTotal have flagged the domain, with 11 of 91 security vendors marking it as malicious. The independent Gridinsoft trust score is 0 out of 100, reinforcing the low trust assessment. The domain appears on a single external blocklist and is actively blocked by PhishDestroy, indicating that at least one threat‑intelligence feed is recognizing the operation.
No nameserver records were retrieved (NS_NOT_FOUND), which may hinder automated DNS‑based detection. Defenders should add the hostname and its resolved IP address to inbound and outbound filtering rules, enforce DNS sinkholing where possible, and monitor for any authentication attempts to corporate services originating from this endpoint. Continuous telemetry collection from web proxy and endpoint logs is advised to capture any attempted credential submissions. Given the confirmed vendor detections, low trust score, and active blocklist status, the domain should be treated as high‑risk and blocked across all security controls pending further investigation.
Copertura dei dati12 recorded checks
Pipeline di risposta alle minacce
Stato della lista di blocco pubblica
Acquisizione salvata
Analisi dei domini
Dettagli tecniciDNS, SAN SSL, timestamp
ICANN OVERSIGHT
Registration: replit.app
Accreditamento e contesto RAA
Accreditamento e contesto RAA
Registrar accreditation and DNS abuse obligations
For the registrable domain replit.app behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Analisi di VirusTotal
Prove archiviate
Analisi delle prestazioni del sito
Google PageSpeed Insights — mobile performance audit of encryptedporfoliodocuments.replit.app · checked Jul 13, 2026
Dati e relazioni esterneIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
Se hai inserito credenziali dell'account, informazioni personali o di pagamento oppure hai scaricato un file da questo dominio, agisci immediatamente. Di seguito sono riportate le risorse per aiutarti a segnalare l'incidente e proteggerti.
Segnalalo alle autorità locali
Seleziona il tuo Paese per ottenere contatti ufficiali del crimine informatico o creare una bozza di reclamo →.