classe2027[.]com
“Classe2027.com â Découvrez votre classe en avance”
Сохранённое наблюдение
Зафиксированное различие заголовков
Сводка доказательств
The domain classe2027.com has been identified as a credential theft operation targeting users through fraudulent educational portal impersonation. Analysis indicates the site masquerades as a legitimate class enrollment platform, using the page title 'Classe2027.com — Découvrez votre classe en avance' to deceive visitors into submitting sensitive login credentials. The domain is currently offline, but prior activity suggests a focused campaign against students or educational institution affiliates. Infrastructure analysis reveals classe2027.com was registered on June 11, 2026, through Global Domain Group LLC and resolved to the IP address 188.114.97.3. The domain is flagged by 5 of 95 security vendors on VirusTotal and appears in 4 threat intelligence pulses on AlienVault OTX. It was blocked by one security blocklist and utilized Cloudflare with HTTP/3 for traffic obfuscation. The SSL certificate was issued by Let’s Encrypt, a common tactic to lend superficial legitimacy to malicious domains. The registration date, while in the future, aligns with patterns observed in phishing domains pre-registered for short-term campaigns. Current status confirms classe2027.com has been taken offline, though the infrastructure may resurface under a different domain or IP. Organizations and individuals are advised to implement DNS-based blocking for the domain and its associated IP (188.114.97.3) as a precautionary measure. Users who interacted with the site should reset credentials for any accounts accessed during the exposure window. Network defenders should monitor for similar domains registered through Global Domain Group LLC or resolving to the same IP range, as these may indicate related threat activity. Educational institutions should alert students and staff to verify URLs before entering credentials, particularly for class-related portals.
Data Coverage
Процесс реагирования на угрозы
Проверка по блок-листам
10 внешних источников под наблюдением · снимок от 11.08.2026
10 внешних источников под наблюдением Совпадений нет
Хронология обнаружения
-
VirusTotal
4 → 5
Аналитика доменов
Технические деталиDNS, имена TLS и временные метки
ICANN OVERSIGHT
Аккредитация и контекст RAA
Аккредитация и контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Технологии
Выявлено 2 технологии с высокой уверенностью
Анализ VirusTotal
Анализ производительности сайта
Google PageSpeed Insights — mobile performance audit of classe2027.com · checked Jun 25, 2026
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание