chatwoot[.]deliverynexus[.]com[.]br
“Chatwoot”
chatwoot.deliverynexus.com.br — Контент недоступен. Сводка доказательств: VirusTotal 4/95 (ChainPatrol, alphaMountain.ai, SOCRadar, Webroot); PhishDestroy score 65/100. Регистратор: HSTDOMAINS.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
This domain, chatwoot.deliverynexus.com.br, is identified as a delivery scam operation designed to deceive users by impersonating legitimate parcel tracking or customer support services. Analysis indicates the infrastructure mimics Chatwoot, an open-source customer engagement platform, likely to exploit trust in branded communication channels. The domain exhibits no direct ties to cryptocurrency drainers or credential theft kits but focuses on fraudulent delivery notifications to manipulate victims into disclosing personal information or making unauthorized payments. Infrastructure analysis reveals the following technical indicators: the domain was registered on October 27, 2025, through HSTDOMAINS and resolves to the IP address 147.93.182.78. VirusTotal reports 4 out of 95 security vendors flagging the domain as malicious, while Gridinsoft assigns a trust score of 0/100. The domain appears on one security blocklist and is currently blocked by at least one threat intelligence feed. No detections from Google Safe Browsing (GSB) were recorded at the time of analysis. As of the latest assessment, chatwoot.deliverynexus.com.br has been taken offline, reducing immediate exposure risk. However, the domain's recent registration and association with a known registrar frequently used for malicious activities suggest residual risk. Organizations and users are advised to monitor for re-emergence under similar subdomains or IP ranges, implement DNS-based blocking for 147.93.182.78, and validate all parcel-related communications through official vendor channels. Continuous threat intelligence monitoring is recommended due to the elevated risk classification.
Данные сетевой безопасности
Процесс реагирования на угрозы
Статус в публичных блок-листах
Анализ VirusTotal
Доказательства и внешние отчеты
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание