phase22[.]co
“Phase 22”
Resumo das evidências
The domain phase22.co was registered on May 12, 2026 and is currently resolved to the IPv4 address 185.158.133.1. Geolocation of the host places it in Germany (DET FRA). The web server presents a TLS certificate issued by Google Trust Services under the WE1 label, indicating the use of a widely trusted certificate authority. An HTTP request to the site returns a 302 redirect, a common technique for steering victims to credential‑harvesting pages.
Infrastructure analysis shows the domain is listed on three security blocklists and has been explicitly blocked by known phishing mitigation filters. The Gridinsoft trust scoring system assigns a score of 0 out of 100, reflecting a complete lack of confidence in the host’s legitimacy. AlienVault OTX references the domain in a single threat‑intel pulse, and VirusTotal reports that one out of ninety‑five scanned security vendors flagged the domain as malicious. These data points collectively reinforce the classification of the site as a high‑risk phishing vector.
The observed evidence points to a generic phishing operation targeting users who may be lured by the page title "Phase 22". While the redirect behavior and blocklist presence confirm malicious intent, the specific phishing kit or credential‑collection method employed remains undetermined from the available data. No additional payload samples, command‑and‑control traffic, or victim reports have been identified, leaving the exact scope of the campaign open to further investigation.
Defenders should immediately block phase22.co at the network perimeter and update endpoint detection rules to flag any outbound connections to 185.158.133.1. Continuous monitoring of DNS queries for this domain is advised, along with periodic re‑scanning on multi‑engine services to capture any changes in the detection profile. Organizations should also educate users about the appearance of the "Phase 22" title to reduce the likelihood of credential submission to the malicious site.
Data Coverage
Pipeline de resposta a ameaças
Cobertura de listas de bloqueio
10 fontes externas monitoradas · instantâneo de 11/08/2026
Inteligência de Domínios
Detalhes técnicosDNS, nomes TLS e datas
Análise do VirusTotal
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo