Ir para o relatório de segurança
Checked 09/08/2026 Ref 63147CDE

MALICIOUS — CRITICAL

Verificação de phishing e segurança de urlwatch.com

urlwatch[.]com

The domain urlwatch.com is currently listed as a high‑risk phishing infrastructure in the July 22 2026 intelligence feed.

80/100 evidence score · Critical
VirusTotal
6/91
Blocklists
No stored match
Disponibilidade
Último ativo conhecido · HTTP 200
Report / Add Evidence Appeal this listing
2026-07-22 09:42 UTCÚltimo ativo conhecido · HTTP 200

Do not enter credentials, seed phrases, payment details, or personal information on this domain.

⚠️
Este domínio foi sinalizado como malicioso
Mecanismos de segurança relatando uma detecção: 6. Tenha extremo cuidado – não insira credenciais ou informações pessoais.
ABUSE NOTICE · 7D+ OPEN Outgoing abuse reports are recorded; the latest stored availability evidence still shows the domain reachable.
Notification and current-status evidence

The sent-report ledger records the first outgoing report at . The recorded recipient is whoisrequest@markmonitor.com. The latest stored availability evidence still shows the domain reachable; 18 days has elapsed since the first outgoing report.

ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.

Elapsed since first report
18 days
Reports sent
1
Latest case ID
PD-20260722-99FCF4
Current status
HTTP 200 at latest stored check
Jump to section
Resumo do relatório

urlwatch.com — Último ativo conhecido (HTTP 200). Resumo das evidências: VirusTotal 6/91 (Chong Lua Dao, Cluster25, CRDF, Forcepoint ThreatSeeker, Gridinsoft); URLQuery 1 alert; PhishDestroy score 80/100. Registrador: MarkMonitor.

A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.

Evidence Analysis

Ref 63147CDE

The domain urlwatch.com is currently listed as a high‑risk phishing infrastructure in the July 22 2026 intelligence feed. The domain was originally registered on 9 March 2000 through MarkMonitor, Inc., and remains active despite its age, a pattern frequently observed in long‑standing abuse campaigns that repurpose legacy domains. DNS resolution points to the IPv4 address 18.245.86.12, hosted on Amazon Web Services as indicated by the four authoritative name servers (ns-1168.awsdns-18.org, ns-1967.awsdns-53.co.uk, ns-421.awsdns-52.com, ns-931.awsdns). The same address is currently observed in active network traffic associated with phishing distribution. Reputation services have flagged the domain on two independent blocklists, specifically PhishDestroy and OpenPhish, confirming that it is already recognized as malicious by external sink‑hole feeds.

VirusTotal analysis shows that four of ninety‑five scanning engines have generated a detection for urlwatch.com, reinforcing the blocklist evidence. No additional public threat‑intel platforms such as OTX or Google Safe Browsing are referenced in the supplied data. The available evidence does not include a page title, SSL certificate details, HTTP response codes, or any observed payload, leaving the exact phishing lure undefined. Consequently, the precise target brand or credential‑stealing technique cannot be confirmed at this time.

Nevertheless, the convergence of blocklist entries, partial VirusTotal detections, and the association with a cloud‑hosted IP address warrants immediate defensive action. Defenders should add urlwatch.com to network‑level deny lists, configure DNS filters to block resolution to 18.245.86.12, and ensure that endpoint security products are updated to reflect the four VirusTotal detections. Continuous monitoring of the domain’s DNS records and any future blocklist inclusions is recommended to capture potential changes in hosting or activity patterns.

Stored source results

Recorded verdicts and infrastructure observations for this domain.

VirusTotal
VirusTotal
6 det.
URLQuery
URLQuery
1 threat alert
URLScan
URLScan
Gridinsoft
92/100
Certificado TLS
Amazon
Idade
26.4 yr
Status observado
Último ativo conhecido 200
PhishDestroy
DestroyList
Listado
Reports Sent
1
Cobertura dos dados13 recorded checks
VirusTotal 6 / 91 URLQuery 1 threat-system alert PhishStats não verificado OTX no community references CF Radar scan completed URLScan capture relatório armazenado URLScan verdict Análise concluída Bloqueios de DNS não verificado TLS valid certificate, 69d WHOIS 322 mo old Captura de tela 3 captures · 3 sources Cadeia de redirecionamentos não investigado Gridinsoft 92/100
Inteligência de segurança de rede
Threat Detection Systems 1 alert
Detection System Indicator Verdict Alert
Hagezi Threat Feed urlwatch.com malicious Sinkholed

Pipeline de resposta a ameaças

Descoberta
Checks
Reports
Disponibilidade
11/12
Ameaça detectada
urlwatch.com detectados e colocados na fila para análise completa
22/07/2026
URLScan.io Capture
Stored URLScan report with capture artifacts
22/07/2026
URLScan Verdict
Análise URLScan concluída; este resultado de captura da web não altera o veredicto de ameaça da página · score 0
29/07/2026
Cloudflare Radar Report
A stored Cloudflare Radar report is available. The report link alone is not a malicious verdict and does not prove that every network field was captured.
Web Archive
Preserved in Wayback Machine — historical evidence archived
22/07/2026
VirusTotal
6/91 recorded on VirusTotal
01/08/2026
Google Safe Browsing
22/07/2026
Forensic Evidence Collected
Stored evidence from URLScan.io, URLQuery, stored screenshot
22/07/2026
Technical Analysis Recorded
O relatório contém tecnologia armazenada ou resultados de análises forenses.
09/08/2026
Sent Report Recorded
Stored sent-report record for registrar MarkMonitor, Inc., hosting provider, 2 abuse contacts
whoisrequest@markmonitor.comabusecomplaints@markmonitor.com
22/07/2026
Lista de Destruição Publicada
22/07/2026
Monitoring Continues
O domínio permanece acessível ou com acesso restrito; verificações futuras poderão atualizar esta observação.

Status da lista de bloqueios pública

Captura armazenada

Título da página
Abnormal AI
Certificado TLS
Valid transport encryption · Emitido por Amazon · valid for 69 days

Inteligência de Domínios

Domínio
URLScan Verdict Análise concluída score 0 report ↗
Servidor / ASN AmazonS3 · AS16509 AMAZON-02 - Amazon.com, Inc., US
Reputação do IP abuse score 0/100 0 reports checked 22/07/2026
Endereço IP 18.245.86.12 DE
LocalizaçãoDE Frankfurt am Main, DE
RedeAS16509 · Amazon.com, Inc.
RegistroCriado 09/03/2000 Expires 09/03/2028
Status HTTP200
Detalhes técnicosDNS, SANs do SSL, carimbos de data e hora
Detectado pela primeira vez22/07/2026
DOM Analysisanalyzed 22/07/2026score 78/100
IoC Extractionscanned 29/07/20260 wallet · 0 Telegram IoCs
Submitted URLhttp://urlwatch.com/urlwatch
Servidores de nomesns-1168.awsdns-18.orgns-1967.awsdns-53.co.ukns-421.awsdns-52.comns-931.awsdns-52.net
TLS Fingerprint
TLS Observationvalid from 16/03/2026scanned 22/07/2026
TLS SAN Domainsrelease.email.abnormalplatform.comtraining.abnormalplatform.comus.release.email.abnormalplatform.comwww.release.email.abnormalplatform.comwww.training.abnormalplatform.comwww.urlwatch.comwww.us.release.email.abnormalplatform.com
Favicon Hash
Case ID
ICANN OVERSIGHT

Credenciamento e contexto RAA

Registrar accreditation and DNS abuse obligations

For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.

Accreditation is a contract, not a safety certification.

RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.

Accountability draft Nada é enviado automaticamente.
Tecnologias · 5 identified
Amazon Web Services
PaaS

Amazon Web Services (AWS) is a comprehensive cloud services platform offering compute power, database storage, content delivery and other functionality.

aws.amazon.com 100% de confiança
Typekit
Font scripts

Typekit is an online service which offers a subscription library of fonts.

typekit.com 100% de confiança
HSTS
Segurança

HTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.

www.rfc-editor.org 100% de confiança
Amazon S3
CDN

Amazon S3 or Amazon Simple Storage Service is a service offered by Amazon Web Services (AWS) that provides object storage through a web service interface.

aws.amazon.com 100% de confiança
Amazon CloudFront
CDN

Amazon CloudFront is a fast content delivery network (CDN) service that securely delivers data, videos, applications, and APIs to customers globally with low latency, high transfer speeds.

aws.amazon.com 100% de confiança
Detected via Cloudflare Radar · Wappalyzer engine
Denunciar este domínio Envie evidências e ajude a proteger outras pessoas

Análise do VirusTotal

6 / Os fornecedores de segurança 91 sinalizaram este domínio
View on VT
Last analyzed First positive detection Previous stored snapshot: 5 detections
Chong Lua Dao
Cluster25
CRDF
Forcepoint ThreatSeeker
Gridinsoft
SafeToOpen

Evidências arquivadas

Wayback Machine Snapshot
Um instantâneo histórico está disponível para revisão de evidências
View Archive
Análise de desempenho do site

Google PageSpeed Insights — mobile performance audit of urlwatch.com · checked Jul 22, 2026

62
Needs Work
Performance
FCP
2.29s
First Contentful Paint
LCP
22.06s
Largest Contentful Paint
CLS
0
Cumulative Layout Shift
TBT
341ms
Total Blocking Time
SI
4.29s
Speed Index
Powered by Google PageSpeed Insights · Mobile strategy · Scores: 90-100 Good 50-89 Needs Work 0-49 Poor
Evidências e relatórios externosIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
If credentials were compromised, report immediately. Do not engage with recovery scammers.

Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.

Europol
Encontre o canal de denúncia oficial do seu país da UE
National police directory
Cuidado com os golpistas que prometem recuperação! Os criminosos podem entrar em contato novamente com as vítimas fingindo ser investigadores, advogados ou agentes de recuperação. Não pague taxas antecipadas nem compartilhe credenciais. Saiba mais sobre fraudes relacionadas à recuperação →

Notifique as autoridades locais

Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.

Diretório de 97 países
Rascunho assistido por IA – os detalhes do incidente são processados pelo provedor de IA Revise e envie você mesmo
Incorporar este relatórioRead-only HTML widget
HTML · IFRAME

Incorporar este relatório

Compartilhe essas informações sobre ameaças em seu site ou blog

embed.html
<iframe
  src="https://phishdestroy.io/pt-br/embed/domain/urlwatch.com"
  title="PhishDestroy threat report for urlwatch.com"
  width="100%" height="320"
  loading="lazy"
  referrerpolicy="no-referrer"
  sandbox="allow-same-origin allow-popups allow-popups-to-escape-sandbox"
  style="border:0;border-radius:12px;max-width:100%"
></iframe>

Uma carta de agradecimento muito sincera

Gerador de rascunho satírico

Destinatário
Contexto das taxas

Rascunho satírico. Os valores das taxas são estimativas; não se afirma que sejam atribuíveis exatamente a este domínio.