MALICIOUS — CRITICAL
blackcatpayments[.]com
Analysis of blackcatpayments.com shows it is an active generic phishing infrastructure observed on 14 July 2026.
- VirusTotal
- 1/91
- Blocklists
- 2 · MetaMask, SEAL
- Доступность
- Контент недоступен · HTTP 502
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
blackcatpayments.com — Контент недоступен (HTTP 502). Сводка доказательств: VirusTotal 1/91 (SOCRadar); URLQuery 1 alert; 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 88/100. Регистратор: Hostinger.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
Evidence Analysis
blackcatpayments.com: Generic Phishing Site
Analysis of blackcatpayments.com shows it is an active generic phishing infrastructure observed on 14 July 2026.
Analysis of blackcatpayments.com shows it is an active generic phishing infrastructure observed on 14 July 2026. The domain resolves to IP address 188.114.96.3 and is served over TLS with a Google Trust Services / WE1 certificate, indicating a valid HTTPS endpoint. Registration records list Hostinger Operations, UAB as the registrar, with the domain creation date of 11 July 2026. DNS is delegated to Cloudflare name servers bailey.ns.cloudflare.com and jaxson.ns.cloudflare.com. The site has been scanned by 91 VirusTotal vendors without any current detections; however, the lack of detections does not confirm safety. The threat is currently classified as generic phishing and remains under investigation. Uncertainty remains regarding the specific content hosted on the site, as no page‑level analysis is available. Defenders should consider adding the domain and its associated IP to blocklists, monitor outbound connections for traffic to the IP, and continue periodic re‑scans to detect any future malicious payloads.
Stored source results
Recorded verdicts and infrastructure observations for this domain.
Охват данных12 recorded checks
Данные сетевой безопасности
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Hagezi Threat Feed | blackcatpayments.com |
malicious | Sinkholed |
Процесс реагирования на угрозы
Статус в публичных блок-листах
Сохранённый снимок
Аналитика доменов
Технические сведенияDNS, SAN в протоколе SSL, временные метки
ICANN OVERSIGHT
Аккредитация и контекст RAA
Аккредитация и контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Анализ VirusTotal
Доказательства и внешние отчетыIndependent lookups and source reports
PD-20260714-20D390 Recipient: abuse-tracker@hostinger.com Victim safety and official reportingImmediate actions and verified reporting channels
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.