77-110-118-2[.]cprapid[.]com
“Explore the future of technology.”
77-110-118-2.cprapid.com — Непроверенный. Сводка доказательств: VirusTotal 12/91 (alphaMountain.ai, BitDefender, Chong Lua Dao, ESET, Forcepoint ThreatSeeker); CF Radar malicious; PhishDestroy score 91/100. Регистратор: Tucows.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
The domain 77-110-118-2.cprapid.com is currently identified as a generic phishing infrastructure, targeting users under the guise of technology-related content. Analysis confirms its status as offline, though prior activity classified it as an active threat vector. No specific brand impersonation has been confirmed, but the domain’s thematic focus on technology suggests potential credential harvesting or malware distribution under the pretext of futuristic innovation. Infrastructure analysis reveals multiple high-risk indicators. The domain was created on May 16, 2019, and is registered through Tucows Domains Inc. It resolves to the IP address 77.110.118.2, geolocated in Germany under autonomous system AS210644, operated by a hosting provider known for high-risk deployments. Security vendors have flagged this domain in 13 of 95 VirusTotal scans, and it appears on two independent security blocklists. The SSL certificate is issued to tg-secret-web.roego.xyz, a mismatch that further undermines trust. The page title, 'Explore the future of technology,' aligns with common phishing lures designed to exploit curiosity or urgency. Current status indicates the domain has been taken offline, reducing immediate exposure. However, residual risks persist due to its historical use and infrastructure. Users are advised to treat any prior interactions with this domain as compromised, particularly if credentials or personal data were submitted. Network administrators should block the IP 77.110.118.2 and monitor for related subdomains or certificates tied to roego.xyz. Security teams should review logs for connections to this infrastructure, especially from May 2019 onward, and assess endpoints for signs of unauthorized access or malware. Proactive measures include updating blocklists and educating users on recognizing phishing themes that leverage technology or innovation as bait.
Сигналы безопасности
Данные сетевой безопасности
Процесс реагирования на угрозы
Статус в публичных блок-листах
Сохранённый снимок
Аналитика доменов
Технические сведенияDNS, SAN в протоколе SSL, временные метки
ICANN OVERSIGHT
Registration: cprapid.com
Аккредитация и контекст RAA
Аккредитация и контекст RAA
Registrar accreditation and DNS abuse obligations
For the registrable domain cprapid.com behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Анализ VirusTotal
Архивные доказательства
Доказательства и внешние отчеты
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание