momentum-recovery[.]ca
“momentum-recovery.ca”
momentum-recovery.ca — 확인되지 않음. 브랜드 사칭: Google; 사기 유형: Tech Support Scam. 증거 요약: VirusTotal 5/91 (ChainPatrol, alphaMountain.ai, CRDF, Gridinsoft, SOCRadar); PhishDestroy score 78/100. 등록기관: Go Daddy Domains Canada.
원본 포렌식 기록을 보존하기 위해 아래의 상세 PhishDestroy AI 분석은 영어로 유지됩니다.
Analysis of momentum-recovery.ca, created on 3 November 2025 and hosted on an Amazon‑owned IP (76.223.105.230, AS16509), shows a high‑risk brand‑impersonation campaign targeting Google users. The domain is registered through Go Daddy Domains Canada, Inc. and uses GoDaddy’s default nameservers (ns09.domaincontrol.com, ns10.domaincontrol.com). It resolves over HTTPS with a Go Daddy Secure Certificate (G2) and returns HTTP 200, indicating an active web service. The page title is the bare domain name, providing no further context. Technical fingerprints reveal the use of GoDaddy Website Builder, RequireJS, reCAPTCHA, Re:amaze live‑chat widget, and enforced HSTS, all typical of a quickly assembled phishing kit.
Infrastructure indicators include a single MX record pointing to momentumrecovery-ca02b.mail.protection.outlook.com, suggesting the operator has provisioned outbound mail capability, potentially to send lure messages. The domain appears on one public blocklist and is explicitly listed by PhishDestroy as malicious. VirusTotal scans have flagged the site by four of ninety‑five security vendors, and Gridinsoft assigns a trust score of zero out of one hundred, reinforcing the malicious assessment. The campaign is classified as a tech‑support scam that masquerades as a Google support request, though the exact content of the landing page has not been captured. Defenders should immediately add momentum-recovery.ca to URL filtering and endpoint allow‑list block rules, monitor outbound connections to the associated MX host, and enforce user education on unsolicited Google support communications.
Given the recent creation date, the domain has not yet accumulated a large reputation history, which limits passive detection and makes proactive blocking essential. The presence of reCAPTCHA suggests an attempt to appear legitimate to browsers, while the Re:amaze widget may be used to collect victim responses in real time.
위협 대응 Pipeline
공개 차단 목록 상태
사용 기술 · 5 identified
Google's bot-challenge service. On phishing sites, used to appear legitimate and filter out automated scanners.
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
VirusTotal 분석
보관된 증거
증거 및 외부 보고서
이 사이트로 인해 영향을 받으셨나요?
계정 자격 증명, 개인 정보 또는 결제 정보를 입력했거나 이 도메인에서 파일을 다운로드한 경우 즉시 조치를 취하세요. 다음은 사건을 신고하고 자신을 보호하는 데 도움이 되는 리소스입니다.
지역 당국에 신고하십시오
공식 사이버 범죄 연락처 또는 불만사항 초안 작성 →를 받으려면 국가를 선택하세요.