refund[.]cat2026[.]icu
“Welcome”
refund.cat2026.icu — 未検証. 証拠の概要: VirusTotal 5/91 (CRDF, Forcepoint ThreatSeeker, Fortinet, Gridinsoft, LevelBlue); Spamhaus DBL_SPAM; PhishDestroy score 78/100.
元のフォレンジック記録を保持するため、下の PhishDestroy AI 詳細分析は英語のままです。
This domain, refund.cat2026.icu, presents a generic page titled "Welcome." Based on the domain name and minimal content, it likely poses as a platform for processing refunds, a common phishing or credential harvesting scheme aimed at collecting financial information from victims.
Technical evidence indicates malicious activity. VirusTotal reports 4/95 detections, with flags from alphaMountain.ai, Fortinet, Seclookup, and SOCRadar. The domain is registered on 2026-02-21, hosted at IP 104.21.50.173 (US) under AS13335 Cloudflare, Inc., and uses SSL type WE1. It appears on 1 blocklist and has a GridinSoft trust score of 0/100.
The domain is currently DOWN/OFFLINE. Its DOM risk score is 56, indicating a high threat level. The site should be treated as malicious and blocked to prevent user interaction.
脅威対応 Pipeline
公開ブロックリスト登録状況
保存済みキャプチャ
ドメイン・インテリジェンス
技術的な詳細DNS、SSL SAN、タイムスタンプ
SHORTDOTゾーン · 公開証拠
.icu
ShortDot zone evidence
ShortDot zone evidence
The linked repository preserves daily zone observations across seven ShortDot-operated TLDs, including registration volume and abuse-related indicators. This registry context is supporting background and is not an independent detection for the domain in this report.
フォレンジックインテリジェンス
VirusTotalによる分析
証拠および外部報告書
このサイトによって何か影響を受けましたか?
アカウント資格情報、個人情報、支払い情報を入力した場合、またはこのドメインからファイルをダウンロードした場合は、すぐに対処してください。インシデントを報告し、自分自身を守るのに役立つリソースを以下に示します。
お住まいの地域の当局へ報告してください
サイバー犯罪の公式連絡先 または 苦情草稿を作成する → を取得するには、国を選択してください。
任意のドメインを確認する
保存されたブロックリスト、WHOIS、DNS、および公開スキャン証拠を使用した脅威分析
今すぐスキャンフィッシングを報告する
不審なドメインを当社の脅威データベースに報告してください — コミュニティを守りましょう
レポートリアルタイム脅威情報フィード
最近のフィッシングレポートと観察された可用性の変化
監視最新情報を入手し、安全を確保しましょう
リアルタイムの脅威を監視するか、誤検知だと思われる場合はこのリストに異議を申し立ててください