adminciwei[.]cc
Verificação de phishing e segurança de adminciwei.cc
“TK-Store | buy, sell and discover on TK”
adminciwei.cc — Conteúdo indisponível (HTTP 502). Representação da marca: Across; Tipo de golpe: Brand Impersonation. Resumo das evidências: VirusTotal 15/95 (ADMINUSLabs, alphaMountain.ai, BitDefender, CyRadar, ESET); URLScan malicious verdict; PhishDestroy score 100/100. Registrador: NameSilo.
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
adminciwei.cc was observed resolving to the IP address 118.107.59.218, which is announced by AS152194 (CTG Server Limited) in Japan. The domain is hosted on Cloudflare DNS as indicated by the authoritative nameservers becky.ns.cloudflare.com and conrad.ns.cloudflare.com. The site lacks an SSL/TLS certificate, causing HTTP connections to be unencrypted. The only visible page title returned during the brief crawl was “TK-Store | buy, sell and discover on TK”, which does not reveal a specific victim brand but aligns with the classified scam type of brand impersonation. The domain was registered on June 17, 2025 through NameSilo, LLC and currently shows an offline HTTP status, indicating the site has been taken down or is otherwise inaccessible.
Reputation services assign extremely low confidence scores: Gridinsoft reports a trust score of 0 out of 100, while Scamadviser records 1 out of 100. The domain appears on a single security blocklist and is explicitly listed by PhishDestroy. AlienVault OTX references the domain in sixteen separate threat‑intelligence pulses, confirming repeated observation by the community. VirusTotal analysis shows fifteen of ninety‑five scanning engines flag the domain as malicious, reinforcing the suspicion of a phishing operation.
The available evidence points to a deliberate brand‑impersonation campaign that uses the generic “TK‑Store” title to lure victims, but the exact targeted brands remain unspecified beyond the generic “across” label. No further technical artifacts such as payload hashes, command‑and‑control endpoints, or malicious scripts have been disclosed. Consequently, defenders should block the domain at DNS and proxy layers, monitor for any residual traffic to the hosting IP, and consider adding the IP address to blacklists used by intrusion‑prevention systems. Continuous re‑query of reputation feeds is advised, as additional detections may emerge while the site remains offline.
Sinais de segurança
Inteligência de segurança de rede Registrar context
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Análise do VirusTotal
Evidências e relatórios externos
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo