vantage-tw[.]co
Verifica phishing e sicurezza per vantage-tw.co
“Vantage: One-Stop Global Investment Platform | Forex | Commodities | Stocks |...”
vantage-tw.co — Contenuto non disponibile (HTTP 502). Tipo di truffa: Investment Scam. Riepilogo delle prove: VirusTotal 12/91 (alphaMountain.ai, BitDefender, CRDF, CyRadar, Forcepoint ThreatSeeker); 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 86/100. Registrar: NameSilo.
L’analisi dettagliata di PhishDestroy AI resta in inglese per preservare il rapporto forense originale.
vantage-tw.co was registered on May 01, 2026 through NameSilo, LLC. The website presents a page titled “Vantage: One-Stop Global Investment Platform | Forex | Commodities | Stocks | Indices | Cryptocurrencies | Gold | Oil”, which mimics a legitimate investment service to lure victims. The content explicitly targets individuals seeking foreign‑exchange and commodity investments, aligning with the observed brand‑impersonation pattern aimed at an investment scam.
Technical resolution points to IP 104.21.57.224, owned by AS13335 Cloudflare, Inc., located in the United States. The domain is served behind Cloudflare’s CDN using the authoritative nameservers lloyd.ns.cloudflare.com and monroe.ns.cloudflare.com. HTTPS is enabled with a valid Let’s Encrypt certificate (CN=E8), and the site returns HTTP 200 for the landing page.
The domain appears on three public blocklists and is actively blocked by PhishDestroy, MetaMask, and SEAL. VirusTotal records a single positive detection out of 95 scanners, while Gridinsoft assigns a trust score of 0 out of 100, indicating extreme suspicion. AlienVault OTX references the domain in two separate threat pulses, reinforcing its association with malicious investment campaigns.
While the current evidence confirms the site’s role in brand‑impersonation for investment fraud, the underlying phishing kit, credential‑harvesting mechanisms, and any downstream command‑and‑control infrastructure remain undocumented. Defenders should add the domain and its resolving IP to block lists, monitor for DNS queries to the associated Cloudflare nameservers, and enforce URL filtering for the page title keywords. Continuous re‑analysis is advised to capture any evolution of the campaign, especially if additional security vendors begin flagging the domain.
Informazioni sulla sicurezza di rete Registrar context
Pipeline di risposta alle minacce
Stato della lista di blocco pubblica
Analisi di VirusTotal
Dati e relazioni esterne
PD-20260623-629506 Recipient: abuse@registry.godaddy Questo sito ti ha influenzato in qualche modo?
Se hai inserito credenziali dell'account, informazioni personali o di pagamento oppure hai scaricato un file da questo dominio, agisci immediatamente. Di seguito sono riportate le risorse per aiutarti a segnalare l'incidente e proteggerti.
Segnalalo alle autorità locali
Seleziona il tuo Paese per ottenere contatti ufficiali del crimine informatico o creare una bozza di reclamo →.
Verifica qualsiasi dominio
Analisi delle minacce utilizzando blocklist archiviate, WHOIS, DNS e prove di scansione pubblica
Scansiona oraSegnala un tentativo di phishing
Segnala i domini sospetti al nostro database delle minacce — proteggi la comunità
SegnalaFeed in tempo reale sulle minacce
Segnalazioni recenti di phishing e modifiche osservate della disponibilità
MonitoraRimani informato, rimani al sicuro
Controlla le minacce in tempo reale oppure contesta questa segnalazione se ritieni che si tratti di un falso positivo