caspianoilngas[.]kz
“Caspian Oil and Gas Supply – Best Oil and Gas Supply”
caspianoilngas.kz — Encoberto · alcançável. Tipo de golpe: Credential Phishing. Resumo das evidências: VirusTotal 5/91 (alphaMountain.ai, CRDF, Gridinsoft, SOCRadar, desenmascara.me); cloaking observed; PhishDestroy score 86/100.
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
This domain, caspianoilngas.kz, is identified as a credential theft phishing site targeting individuals and organizations in the oil and gas sector. The fraudulent webpage impersonates Caspian Oil and Gas Supply, a legitimate energy supplier, by replicating its branding, page structure, and content to deceive visitors into submitting sensitive login credentials or corporate access details. Analysis indicates the site is designed to harvest usernames, passwords, and potentially multi-factor authentication tokens, which could lead to unauthorized access to internal systems, financial fraud, or data exfiltration. Infrastructure analysis reveals the domain resolves to the IP address 198.251.84.200 and is hosted on a server running WordPress, MySQL, PHP, and LiteSpeed technologies. Detection metrics confirm its malicious nature, with 2 out of 95 security vendors on VirusTotal flagging the domain as malicious. Additionally, the domain appears on one security blocklist and is actively blocked by enterprise-grade threat intelligence platforms. The SSL certificate is issued by a non-standard provider, further indicating its use in fraudulent activities rather than legitimate business operations. Individuals who have visited caspianoilngas.kz or entered credentials on the site should take immediate action to mitigate potential risks. First, reset all passwords associated with the account, prioritizing those used for corporate email, financial systems, or other sensitive platforms. Enable multi-factor authentication where available to add an additional layer of security. Monitor accounts for unauthorized transactions or suspicious activity and report any anomalies to the appropriate IT or security team. If corporate credentials were exposed, notify the organization’s security operations center to initiate incident response protocols and prevent lateral movement within the network.
Inteligência de segurança de rede
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Tecnologias · 11 identified
WordPress is a free and open-source content management system written in PHP and paired with a MySQL or MariaDB database. Features include a plugin architecture and a template system.
wordpress.org 100% de confiançaUnderscore.js is a JavaScript library which provides utility functions for common programming tasks. It is comparable to features provided by Prototype.js and the Ruby language, but opts for a functional programming design instead of extending object prototypes.
underscorejs.org 100% de confiançaSwiper is a JavaScript library that creates modern touch sliders with hardware-accelerated transitions.
swiperjs.com 100% de confiançaModernizr is a JavaScript library that detects the features available in a user's browser.
modernizr.com 100% de confiançaQuery Migrate is a javascript library that allows you to preserve the compatibility of your jQuery code developed for versions of jQuery older than 1.9.
github.com 100% de confiançajQuery is a JavaScript library which is a free, open-source software designed to simplify HTML DOM tree traversal and manipulation, as well as event handling, CSS animation, and Ajax.
jquery.com 100% de confiançaHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100% de confiançaAnálise do VirusTotal
Análise de desempenho do site
Google PageSpeed Insights — mobile performance audit of caspianoilngas.kz · checked Jun 26, 2026
Evidências e relatórios externos
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo