impressengineering[.]co[.]ke
“Home - Impress Engineering”
Resumo das evidências
The domain impressengineering.co.ke is currently active and resolves to the IPv4 address 46.165.235.143, which is advertised as part of AS28753 Leaseweb Deutschland GmbH located in Germany. The site returns HTTP 200 and presents a page title of “Home - Impress Engineering”. Technical fingerprinting reveals a WordPress stack backed by MySQL and PHP, served through LiteSpeed, and includes front‑end libraries such as Swiper, jQuery, jQuery Migrate and Font Awesome. The domain was registered on 8 November 2023 through HostPinnacle Cloud Limited and uses a Let’s Encrypt R12 certificate, indicating that TLS is properly configured.
VirusTotal records show that two of ninety‑three scanning engines have flagged the domain, and the domain is listed on two public blocklists, specifically PhishDestroy and ScamSniffer. Both blocklists classify the activity as banking phishing, which aligns with the supplied scam type label. Nameservers rs51‑rs54.rcnoc.com are associated with the same hosting provider. No additional intelligence on the page content or the specific credential‑harvesting mechanism is presently available, so the exact phishing lure remains unconfirmed.
However, the combination of a recent registration, active hosting, a valid TLS certificate, and detection by multiple security vendors and blocklists strongly suggests a malicious intent aimed at credential theft. Defensive teams should continue to block the domain at network perimeters, add the IP address 46.165.235.143 to deny‑list rules, and monitor DNS queries for the associated nameservers. Organizations that process banking credentials should treat any communications from this domain as hostile and educate users to avoid interacting with the site. Continuous re‑scanning on VirusTotal and inclusion in threat‑intel feeds are recommended to capture any future changes in the payload or hosting infrastructure.
Data Coverage
Pipeline de resposta a ameaças
Cobertura de listas de bloqueio
10 fontes externas monitoradas · instantâneo de 12/08/2026
9 fontes externas monitoradas Sem correspondência
Linha do tempo de detecção
-
Status do domínio
Acessível → Inacessível
-
Cloudflare Radar
Varredura do Cloudflare Radar armazenada · Abrir varredura
Análise do VirusTotal
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo