Notification and current-status evidence
The sent-report ledger records the first outgoing report at .
The recorded recipient is domain.operations@web.com.
The latest stored availability evidence still shows the domain reachable; 5 months has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
dtw[.]qlp[.]mybluehost[.]me
“Welcome -”
dtw.qlp.mybluehost.me — 확인되지 않음. 증거 요약: VirusTotal 4/91 (alphaMountain.ai, Gridinsoft, LevelBlue, Webroot); URLQuery 1 alert; PhishDestroy score 71/100. 등록기관: Domain.com.
원본 포렌식 기록을 보존하기 위해 아래의 상세 PhishDestroy AI 분석은 영어로 유지됩니다.
Analysis of dtw.qlp.mybluehost.me indicates a high‑risk generic phishing operation that remains active. The domain was registered on February 27, 2026 through Domain.com and is hosted on a shared Bluehost environment, employing a typical WordPress stack with MySQL, PHP, Yoast SEO, Nginx and Apache HTTP Server. DNS resolution points to IP 69.6.192.198, which geolocates to Spain and is announced by AS31898 (Oracle Corporation). The web server presents a 302 redirect and the page title returned is "Welcome -"; no additional content has been catalogued. The domain is listed on a security blocklist, has been blocked by PhishDestroy, and six of ninety‑three VirusTotal scanners have flagged it as malicious. The SSL certificate is issued by Let’s Encrypt (R13), and the Gridinsoft trust score is 0/100, reinforcing the malicious assessment. Defenders should immediately block both the domain and its resolved IP, monitor outbound traffic for connections to the host, and add the domain to internal threat intel feeds. Continuous observation of any changes to the redirect target or page content is recommended, as the current evidence points to a phishing campaign despite limited visible payload.
네트워크 보안 인텔리전스
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DNS4EU | dtw.qlp.mybluehost.me |
malicious | Sinkholed |
위협 대응 Pipeline
공개 차단 목록 상태
사용 기술 · 7 identified
Open-source CMS powering over 40% of websites worldwide.
Open-source relational database management system.
Server-side scripting language designed for web development.
High-performance HTTP server and reverse proxy, known for stability and low resource usage.
Most widely used open-source HTTP server software.
VirusTotal 분석
보관된 증거
사이트 성능 분석
Google PageSpeed Insights — mobile performance audit of dtw.qlp.mybluehost.me · checked Mar 2, 2026
증거 및 외부 보고서
PD-20260227-8CCE4F Recipient: domain.operations@web.com 이 사이트로 인해 영향을 받으셨나요?
계정 자격 증명, 개인 정보 또는 결제 정보를 입력했거나 이 도메인에서 파일을 다운로드한 경우 즉시 조치를 취하세요. 다음은 사건을 신고하고 자신을 보호하는 데 도움이 되는 리소스입니다.
지역 당국에 신고하십시오
공식 사이버 범죄 연락처 또는 불만사항 초안 작성 →를 받으려면 국가를 선택하세요.