MALICIOUS — CRITICAL
Verificação de phishing e segurança de urlwatch.com
urlwatch[.]
The domain urlwatch.com is currently listed as a high‑risk phishing infrastructure in the July 22 2026 intelligence feed.
- VirusTotal
- 6/91
- Blocklists
- No stored match
- Disponibilidade
- Último ativo conhecido · HTTP 200
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Notification and current-status evidence
The sent-report ledger records the first outgoing report at .
The recorded recipient is whoisrequest@markmonitor.com.
The latest stored availability evidence still shows the domain reachable; 18 days has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
Jump to section
urlwatch.com — Último ativo conhecido (HTTP 200). Resumo das evidências: VirusTotal 6/91 (Chong Lua Dao, Cluster25, CRDF, Forcepoint ThreatSeeker, Gridinsoft); URLQuery 1 alert; PhishDestroy score 80/100. Registrador: MarkMonitor.
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
Evidence Analysis
The domain urlwatch.com is currently listed as a high‑risk phishing infrastructure in the July 22 2026 intelligence feed. The domain was originally registered on 9 March 2000 through MarkMonitor, Inc., and remains active despite its age, a pattern frequently observed in long‑standing abuse campaigns that repurpose legacy domains. DNS resolution points to the IPv4 address 18.245.86.12, hosted on Amazon Web Services as indicated by the four authoritative name servers (ns-1168.awsdns-18.org, ns-1967.awsdns-53.co.uk, ns-421.awsdns-52.com, ns-931.awsdns). The same address is currently observed in active network traffic associated with phishing distribution. Reputation services have flagged the domain on two independent blocklists, specifically PhishDestroy and OpenPhish, confirming that it is already recognized as malicious by external sink‑hole feeds.
VirusTotal analysis shows that four of ninety‑five scanning engines have generated a detection for urlwatch.com, reinforcing the blocklist evidence. No additional public threat‑intel platforms such as OTX or Google Safe Browsing are referenced in the supplied data. The available evidence does not include a page title, SSL certificate details, HTTP response codes, or any observed payload, leaving the exact phishing lure undefined. Consequently, the precise target brand or credential‑stealing technique cannot be confirmed at this time.
Nevertheless, the convergence of blocklist entries, partial VirusTotal detections, and the association with a cloud‑hosted IP address warrants immediate defensive action. Defenders should add urlwatch.com to network‑level deny lists, configure DNS filters to block resolution to 18.245.86.12, and ensure that endpoint security products are updated to reflect the four VirusTotal detections. Continuous monitoring of the domain’s DNS records and any future blocklist inclusions is recommended to capture potential changes in hosting or activity patterns.
Stored source results
Recorded verdicts and infrastructure observations for this domain.
Cobertura dos dados13 recorded checks
Inteligência de segurança de rede
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Hagezi Threat Feed | urlwatch.com |
malicious | Sinkholed |
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Captura armazenada
Inteligência de Domínios
Detalhes técnicosDNS, SANs do SSL, carimbos de data e hora
ICANN OVERSIGHT
Credenciamento e contexto RAA
Credenciamento e contexto RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Tecnologias · 5 identified
Amazon Web Services (AWS) is a comprehensive cloud services platform offering compute power, database storage, content delivery and other functionality.
aws.amazon.com 100% de confiançaTypekit is an online service which offers a subscription library of fonts.
typekit.com 100% de confiançaHTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org 100% de confiançaAmazon S3 or Amazon Simple Storage Service is a service offered by Amazon Web Services (AWS) that provides object storage through a web service interface.
aws.amazon.com 100% de confiançaAmazon CloudFront is a fast content delivery network (CDN) service that securely delivers data, videos, applications, and APIs to customers globally with low latency, high transfer speeds.
aws.amazon.com 100% de confiançaAnálise do VirusTotal
Evidências arquivadas
Análise de desempenho do site
Google PageSpeed Insights — mobile performance audit of urlwatch.com · checked Jul 22, 2026
Evidências e relatórios externosIndependent lookups and source reports
PD-20260722-99FCF4 Recipient: whoisrequest@markmonitor.com Victim safety and official reportingImmediate actions and verified reporting channels
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.