changeenow[.]org
“changeenow.org”
Сводка доказательств
changeenow.org was observed hosting a generic phishing page. The site was first seen after its registration on 21 February 2026 and was taken offline before the report date of 24 July 2026. DNS resolution points to the IPv4 address 64.190.63.222, which belongs to the German autonomous system AS47846 operated by SEDO GmbH. The server presents an SSL certificate issued by Encryption Everywhere DV TLS CA – G2, indicating that TLS is correctly configured but does not imply legitimacy. The page title returned by the HTTP response is simply “changeenow.org”, providing no additional context about the targeted brand or credential‑harvesting technique.
Reputation services have flagged the domain: it appears on one security blocklist and is listed as blocked by the PhishDestroy feed. The Gridinsoft trust score is 0 out of 100, reflecting a complete lack of trust. VirusTotal analysis shows that 12 of 93 antivirus and URL scanners label the domain as malicious, reinforcing the suspicion of phishing activity. No further public intelligence such as Safe Browsing or OTX entries is available, and the exact phishing lure (e.g., login portal, payment page) remains unknown.
Defenders should continue to block the domain at network perimeter and DNS layers, monitor for any residual connections to the hosting IP, and consider adding the address to internal blacklists. Threat hunting should include correlation of recent credential‑theft alerts with traffic to 64.190.63.222 during the active window. Because the site is offline, active remediation is limited to preventing re‑use of the same infrastructure. Ongoing observation of the AS47846 blocklist and PhishDestroy feed is recommended to detect potential re‑deployment of similar phishing domains.
Data Coverage
Процесс реагирования на угрозы
Проверка по блок-листам
10 внешних источников под наблюдением · снимок от 11.08.2026
10 внешних источников под наблюдением Совпадений нет
Криминалистическая аналитика
Анализ VirusTotal
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание