0i-m4[.]fwh[.]is
“Domain Suspended”
0i-m4.fwh.is — Непроверенный. Тип мошенничества: Account Takeover. Сводка доказательств: VirusTotal 15/95 (BitDefender, CyRadar, ESET, Emsisoft, Fortinet); Spamhaus DBL_PHISH; PhishDestroy score 100/100. Регистратор: UK-IFASTNET-20130530 (….
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
This domain, 0i-m4.fwh.is, is identified as a credential harvesting or fake login portal designed to deceive users into submitting sensitive authentication details. Analysis indicates the site was structured to mimic legitimate login pages, likely targeting corporate, financial, or personal accounts. The domain’s infrastructure and rapid takedown suggest a short-lived but high-risk operation typical of phishing campaigns aimed at quick data exfiltration. Technical evidence confirms the domain’s malicious nature. The domain was registered on November 1, 2024, through a registrar associated with ASN 34119, and resolved to the IP address 77.72.1.44, hosted by AS12488 in the United Kingdom. At the time of assessment, 15 out of 95 security vendors on VirusTotal flagged the domain as malicious. Additionally, the domain appears on two security blocklists, including entries from independent phishing detection systems. The absence of an SSL certificate further indicates a lack of basic security measures, a common trait in low-effort phishing infrastructure. Users who visited 0i-m4.fwh.is or interacted with its content should take immediate remediation steps. If credentials were entered, reset passwords for all potentially affected accounts, prioritizing those with financial or administrative access. Enable multi-factor authentication where available to mitigate unauthorized access. Monitor accounts for unusual activity, such as unauthorized logins or transactions. Organizations should review logs for connections to 77.72.1.44 or the domain itself and update blocklists to prevent future access. Given the domain’s current offline status, further interaction is unlikely, but vigilance is advised for similar threats using the same infrastructure.
Сигналы безопасности
Процесс реагирования на угрозы
Статус в публичных блок-листах
Анализ VirusTotal
Архивные доказательства
Доказательства и внешние отчеты
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание