pc[.]libertvip[.]cc
“LIBERTY”
pc.libertvip.cc — Conteúdo indisponível. Tipo de golpe: Generic Phishing. Resumo das evidências: VirusTotal 5/94 (CyRadar, ESET, Forcepoint ThreatSeeker, Netcraft, SOCRadar); 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 70/100. Registrador: Gname.
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
On 24 July 2026 the domain pc.libertvip.cc was observed to host a generic phishing page titled “LIBERTY”. The domain was registered on 2 April 2025 through Gname.com Pte. Ltd. and is currently pointing to the Cloudflare edge address 104.21.87.226, which belongs to AS13335 Cloudflare, Inc. and resolves to a United States location. DNS resolution is served by the Cloudflare authoritative nameservers gwen.ns.cloudflare.com and rohin.ns.cloudflare.com. The web application employs Ant Design and Vue.js frameworks, and traffic is delivered via Cloudflare Browser Insights and HTTP/3, indicating the use of modern CDN services.
VirusTotal scans show that five of ninety‑four antivirus and URL‑reputation engines flagged the domain, confirming malicious classification. The domain appears on three external blocklists and has been actively blocked by PhishDestroy, MetaMask, and SEAL, suggesting that multiple security vendors have added it to their phishing mitigation lists. No additional open‑source intelligence (OTX, public threat feeds) was found beyond the listed blocklist entries. The site’s current HTTP status is offline, which may be a temporary takedown or an attempt to evade detection.
Because the underlying infrastructure – Cloudflare CDN and a generic front‑end stack – is commonly leveraged by threat actors, the offline state does not guarantee the cessation of malicious activity; the domain could be re‑activated or used in a fast‑flux manner. Defenders should continue to block pc.libertvip.cc at network perimeters and endpoint filters, monitor DNS queries for this FQDN, and consider adding it to internal allow‑list exceptions only after thorough validation. Threat‑intel teams should track any re‑appearance of the domain on blocklists or new VirusTotal submissions, and should investigate any related domains that share the same registrar or nameserver configuration for possible campaign linkage.
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Tecnologias · 5 identified
Progressive JavaScript framework for building user interfaces.
Performance monitoring tool that measures website speed from real users.
www.cloudflare.comWeb infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
Análise do VirusTotal
Evidências e relatórios externos
PD-20260316-C79BD0 Recipient: complaint@gname.com Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo