itrustcapitalniclogin[.]webflow[.]io
“404 - Page not found”
itrustcapitalniclogin.webflow.io — Conteúdo indisponível. Tipo de golpe: Credential Phishing. Resumo das evidências: VirusTotal 16/95 (ADMINUSLabs, alphaMountain.ai, BitDefender, CyRadar, ESET); Google Safe Browsing flagged; CF Radar malicious; PhishDestroy score 95/100. Registrador: MarkMonitor.
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
This domain, itrustcapitalniclogin.webflow.io, is flagged as a high-risk credential phishing site targeting iTrustCapital, a cryptocurrency investment platform. Analysis indicates the domain was created on May 8, 2013, but the subdomain or its malicious use appears recent, as it is currently offline with an HTTP 404 status. Infrastructure analysis reveals the domain resolves to Cloudflare IP 2606:4700:4400::ac40:9708 (AS13335, US) and uses Cloudflare nameservers (journey.ns.cloudflare.com, lamar.ns.cloudflare.com). The SSL certificate is issued by Google Trust Services (WE1), a common choice for both legitimate and malicious sites leveraging Cloudflare's CDN.
Google Safe Browsing explicitly flags this domain for social engineering, aligning with its classification as a credential phishing threat. The domain appears on one security blocklist, and 16 of 95 security vendors on VirusTotal detect it as malicious. The registrar is MarkMonitor, Inc., a provider frequently used for both legitimate and fraudulent domains. No specific phishing kit or additional page content (beyond the 404 error) is confirmed in the available data, though the domain name structure suggests an intent to impersonate iTrustCapital's login portal.
Defenders should treat this domain as compromised and block all resolutions at the DNS level. Given its current offline status, monitoring for reactivation is recommended, particularly if the target organization (iTrustCapital) is within scope. If logs show internal users accessed this domain prior to takedown, initiate credential reset procedures for potentially exposed accounts. The use of Cloudflare hosting and Google Trust Services SSL does not indicate legitimacy, as these services are routinely abused for phishing infrastructure.
Inteligência de segurança de rede
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Tecnologias · 2 identified
Web infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
Análise do VirusTotal
Evidências arquivadas
Evidências e relatórios externos
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo