att[.]ilkkd[.]cc
att.ilkkd.cc — 콘텐츠를 사용할 수 없음 (HTTP 502). 브랜드 사칭: Genericcloudflare. 증거 요약: VirusTotal 15/93 (Cluster25, CRDF, Forcepoint ThreatSeeker, Fortinet, Google Safebrowsing); URLScan malicious verdict; Spamhaus DBL_PHISH; PhishDestroy score 95/100.
원본 포렌식 기록을 보존하기 위해 아래의 상세 PhishDestroy AI 분석은 영어로 유지됩니다.
Analysis of the domain att.ilkkd.cc shows it was created on 21 February 2026 and resolves to the IPv6 address 2606:4700:3034::6815:4769, an address owned by Cloudflare, Inc. (AS13335) and geolocated to the United States. The TLS certificate presented for the host is listed as “WE1”, a generic certificate that provides no organisational validation. VirusTotal records detections from 15 of 93 scanned security vendors, indicating that a notable minority of scanners have flagged the domain as malicious. The Gridinsoft trust score is 0 / 100, reinforcing the assessment of high risk.
The domain appears on one external security blocklist and has been actively blocked by the PhishDestroy mitigation service. Current probes indicate the host is offline, suggesting the operator has temporarily taken the site down, but the underlying Cloudflare front‑end and IPv6 address remain reachable and could be re‑activated at any time. No page title, brand identifier, or phishing‑kit details have been observed in the available intelligence, so the exact lure or target brand cannot be confirmed. Nonetheless, the combination of recent registration, low‑trust SSL, multiple vendor detections, inclusion on a phishing‑specific blocklist, and the presence of a Cloudflare‑hosted address satisfies criteria for an elevated‑risk phishing infrastructure.
Defenders should add the fully qualified domain name att.ilkkd.cc and its IPv6 address to network‑level deny lists, configure DNS resolvers to block queries for the domain, and monitor traffic to the associated Cloudflare address for any re‑appearance. Email security gateways should be instructed to quarantine messages that contain URLs resolving to this domain, and user awareness training should highlight the possibility of future campaigns employing similar sub‑domains. Continuous re‑scanning with sandbox and URL‑reputation services is recommended to capture any changes if the site is re‑hosted or the certificate is renewed.
위협 대응 Pipeline
공개 차단 목록 상태
포렌식 인텔리전스
VirusTotal 분석
증거 및 외부 보고서
이 사이트로 인해 영향을 받으셨나요?
계정 자격 증명, 개인 정보 또는 결제 정보를 입력했거나 이 도메인에서 파일을 다운로드한 경우 즉시 조치를 취하세요. 다음은 사건을 신고하고 자신을 보호하는 데 도움이 되는 리소스입니다.
지역 당국에 신고하십시오
공식 사이버 범죄 연락처 또는 불만사항 초안 작성 →를 받으려면 국가를 선택하세요.