Notification and current-status evidence
The sent-report ledger records the first outgoing report at .
The recorded recipient is abuse@timeweb.ru.
The latest stored availability evidence still shows the domain reachable; 7 months has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
cb773971[.]tw1[.]ru
“cb773971.tw1.ru/depart.php”
cb773971.tw1.ru — Непроверенный. Олицетворение бренда: Sei; Тип мошенничества: Brand Impersonation. Сводка доказательств: VirusTotal 13/91 (ADMINUSLabs, alphaMountain.ai, BitDefender, ESET, Forcepoint ThreatSeeker); URLQuery 5 alerts; URLScan malicious verdict; Google Safe Browsing flagged; CF Radar malicious; PhishDestroy score 93/100. Регистратор: TIMEWEB-RU.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
Analysis of the domain cb773971.tw1.ru indicates active brand impersonation targeting SEI, a classification supported by multiple technical indicators. The domain was registered on June 29, 2006, through TIMEWEB-RU, a registrar frequently associated with compromised or malicious infrastructure. Infrastructure analysis reveals the domain resolves to the IP address 87.249.38.179, located in Russia under AS9123 (JSC TIMEWEB), a network segment previously observed hosting phishing campaigns. The domain's nameservers (ns1.timeweb.ru, ns2.timeweb.ru, ns3.timeweb.org) further link it to TIMEWEB's hosting environment, which has been documented in abuse reports for facilitating fraudulent activity. Google Safe Browsing has flagged the domain with the label 'SOCIAL_ENGINEERING,' a designation consistent with phishing or brand impersonation tactics. The page title 'cb773971.tw1.ru/depart.php' suggests the presence of a server-side script, a common feature in credential-harvesting or data-exfiltration schemes. While the exact content of the page remains unanalyzed, the combination of a 302 HTTP redirect, a low Gridinsoft trust score of 0/100, and detection by 15 of 93 security vendors on VirusTotal reinforces the classification of high-risk activity. The domain is currently blocked by PhishDestroy and appears on at least one security blocklist, indicating prior identification as malicious. Defenders should treat this domain as confirmed malicious infrastructure. The SSL certificate issued by GlobalSign nv-sa (GlobalSign GCC R3 DV TLS CA 2020) does not mitigate the risk, as certificates of this type are routinely abused in phishing operations. Network-level blocking of 87.249.38.179 and monitoring for connections to cb773971.tw1.ru are recommended. Given the domain's age and persistent activity, it may be part of a larger, long-running campaign. Further investigation into associated IPs, subdomains, or redirect chains could uncover additional compromised assets.
Данные сетевой безопасности
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Cloudflare DNS | cb773971.tw1.ru |
malicious | Sinkholed |
| OpenDNS | cb773971.tw1.ru |
phishing | Phishing Block |
| DNS0 Zero | cb773971.tw1.ru |
malicious | Sinkholed |
| Quad9 DNS | cb773971.tw1.ru |
malicious | Sinkholed |
| PhishTank | cb773971.tw1.ru/depart.php |
phishing | Phishing - Other |
Процесс реагирования на угрозы
Статус в публичных блок-листах
Анализ VirusTotal
Архивные доказательства
Доказательства и внешние отчеты
PD-20260107-0F475B Recipient: abuse@timeweb.ru Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание