post[.]ch-zahlungssystem[.]sale
post.ch-zahlungssystem.sale — コンテンツが利用できません (HTTP 502). 証拠の概要: VirusTotal 15/93 (ADMINUSLabs, Criminal IP, BitDefender, CRDF, CyRadar); Spamhaus DBL_PHISH; PhishDestroy score 95/100.
元のフォレンジック記録を保持するため、下の PhishDestroy AI 詳細分析は英語のままです。
The domain post.ch-zahlungssystem.sale was registered on February 21, 2026 and currently resolves to the IPv4 address 172.67.174.247, which is owned by Cloudflare, Inc. (AS13335) and geolocated to the United States. The domain’s SSL certificate is identified as WE1, indicating a valid TLS layer but offering no additional trust signals. VirusTotal has recorded 15 positive detections out of 93 scanned security vendors, confirming that multiple independent scanners flag the domain as malicious. It appears on a single public blocklist and is actively blocked by the PhishDestroy service, reinforcing the consensus that the domain is being used for phishing.
The threat classification supplied is “generic phishing,” and the risk level is elevated. The site has been taken offline, as indicated by the status flag, and no HTTP response body or page title is available for further analysis. Defenders should add the IP address 172.67.174.247 to network‑level deny lists only after confirming that legitimate services are not hosted on the same address, recognizing that Cloudflare’s shared infrastructure may host unrelated traffic. The domain name itself should be added to URL filtering and email security policies to block any future attempts to reference it.
Continuous monitoring of the associated IP and ASN for new malicious domains is advised, as threat actors frequently reuse Cloudflare edge nodes. Because the domain is already flagged by VirusTotal and PhishDestroy, automated blocklist feeds will likely capture future re‑registrations, but manual rule updates provide an additional safety net. Until further forensic evidence, such as page content or credential harvesting behavior, becomes available, the recommendation is to treat post.ch‑zahlungssystem.sale as a high‑confidence phishing indicator and enforce strict deny controls across perimeter defenses.
脅威対応 Pipeline
公開ブロックリスト登録状況
フォレンジックインテリジェンス
VirusTotalによる分析
証拠および外部報告書
このサイトによって何か影響を受けましたか?
アカウント資格情報、個人情報、支払い情報を入力した場合、またはこのドメインからファイルをダウンロードした場合は、すぐに対処してください。インシデントを報告し、自分自身を守るのに役立つリソースを以下に示します。
お住まいの地域の当局へ報告してください
サイバー犯罪の公式連絡先 または 苦情草稿を作成する → を取得するには、国を選択してください。
任意のドメインを確認する
保存されたブロックリスト、WHOIS、DNS、および公開スキャン証拠を使用した脅威分析
今すぐスキャンフィッシングを報告する
不審なドメインを当社の脅威データベースに報告してください — コミュニティを守りましょう
レポートリアルタイム脅威情報フィード
最近のフィッシングレポートと観察された可用性の変化
監視最新情報を入手し、安全を確保しましょう
リアルタイムの脅威を監視するか、誤検知だと思われる場合はこのリストに異議を申し立ててください