salzburgweltreisen[.]de
“Payload Website Template”
salzburgweltreisen.de — Não verificado. Resumo das evidências: VirusTotal 3/91 (alphaMountain.ai, CRDF, Gridinsoft); 1 external blocklist match (ScamSniffer); PhishDestroy score 71/100.
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
This domain, salzburgweltreisen.de, was observed hosting a generic phishing site that has been taken offline as of the report date. DNS resolution points to the IPv4 address 202.61.197.60, which is allocated to netcup GmbH under ASN 197540 and geolocated to Germany. The authoritative nameservers are root-dns.netcup.net, second-dns.netcup.net, and third-dns.netcup.net, confirming the netcup hosting environment. No TLS certificate is presented, indicating the site was served over plain HTTP.
The page title returned by the HTTP response is “Payload Website Template”, suggesting the use of a reusable phishing template rather than a targeted brand page. VirusTotal records show that four of ninety‑three scanning engines flagged the domain, demonstrating partial detection across the security community. The domain is listed on two independent phishing blocklists, PhishDestroy and ScamSniffer, and receives a Gridinsoft trust score of 0 out of 100, reinforcing its malicious classification. The site’s current status is offline, preventing further live analysis.
However, the lack of SSL, the generic page title, and the low trust score provide strong indicators of malicious intent. Uncertainty remains regarding the exact phishing campaign payload, target victims, and whether additional infrastructure (e.g., command‑and‑control servers) is associated with the same IP address. Defenders should immediately block DNS resolution to 202.61.197.60 and add salzburgweltreisen.de to web‑filter deny lists. Continuous monitoring of the netcup IP range for new domains and periodic re‑scanning of the host are advised to detect potential re‑use of the infrastructure.
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Análise do VirusTotal
Evidências arquivadas
Evidências e relatórios externos
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo