Перейти к отчёту о безопасности
Checked 09.08.2026 Ref 6F4B391B

MALICIOUS — HIGH

Проверка домена cormentc2.web.id на фишинг и безопасность

cormentc2[.]web[.]id

The domain cormentc2.web.id has been flagged as a generic phishing threat, currently under investigation.

65/100 evidence score · High
VirusTotal
4/91
Blocklists
No stored match
Доступность
Контент недоступен · HTTP 502
Report / Add Evidence Appeal this listing
2026-04-29 16:29 UTCКонтент недоступен · HTTP 502

Do not enter credentials, seed phrases, payment details, or personal information on this domain.

⚠️
Этот домен был отмечен как вредоносный
Механизмы безопасности сообщают об обнаружении: 4. Будьте предельно осторожны — не вводите учетные данные или личную информацию.
Jump to section
Краткий обзор отчёта

cormentc2.web.id — Контент недоступен (HTTP 502). Олицетворение бренда: ["telegram"]; Тип мошенничества: Credential Phishing. Сводка доказательств: VirusTotal 4/91 (alphaMountain.ai, CRDF, Gridinsoft, SOCRadar); PhishDestroy score 65/100. Регистратор: PT JC Indonesia.

Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.

Evidence Analysis

Ref 6F4B391B

The domain cormentc2.web.id has been flagged as a generic phishing threat, currently under investigation. This site impersonates a Cloudflare verification page, as indicated by the title "Just a moment...", a common tactic to steal login credentials. No specific drainer kit has been identified, but the page is designed to harvest sensitive information from unsuspecting visitors.

Technical analysis reveals that the domain was created on April 28, 2026, through the Indonesian registrar PT JC Indonesia, and resolves to IP address 188.114.97.3. It uses an SSL certificate issued by Google Trust Services (WE1). VirusTotal reports 0 out of 95 security vendors have flagged the domain, meaning it has not yet been widely detected as malicious. However, it appears on one security blocklist and is currently listed in Google Safe Browsing as a threat, indicating it poses a risk to users.

The domain has been taken offline, which is a positive development, but the threat remains for any users who may have visited it before takedown. PhishDestroy recommends that anyone who interacted with this site change their passwords immediately and enable two-factor authentication on affected accounts. Users should also monitor for any suspicious activity related to their credentials. The low detection rate on VirusTotal underscores the importance of relying on multiple security layers rather than a single antivirus solution.

Stored source results

Recorded verdicts and infrastructure observations for this domain.

VirusTotal
VirusTotal
4 det.
Сертификат TLS
Google Trust Services
Возраст
3 mo
Зафиксированный статус
Контент недоступен 502
PhishDestroy
DestroyList
В списке
Охват данных12 recorded checks
VirusTotal 4 / 91 URLQuery checked — no detections recorded PhishStats checked — no match recorded OTX no community references CF Radar scan completed URLScan capture сохраненный отчет URLScan verdict Анализ завершён DNS-блокировки 12 проверено — блокировок нет TLS valid certificate, 89d WHOIS 3 mo old Снимок экрана 2 captures · 2 sources Цепочка перенаправлений не исследовано

Процесс реагирования на угрозы

Открытие
Checks
Reports
Доступность
12/13
Угроза устранена
cormentc2.web.id обнаружены и помещены в очередь для полного анализа
29.04.2026
URLScan.io Capture
Stored URLScan report with capture artifacts
URLScan Verdict
Анализ URLScan завершен; этот результат веб-захвата не меняет вердикт об угрозе странице · score 0
29.07.2026
Cloudflare Radar Report
A stored Cloudflare Radar report is available. The report link alone is not a malicious verdict and does not prove that every network field was captured.
VirusTotal
4/91 recorded on VirusTotal
01.08.2026
Google Safe Browsing
29.04.2026
Brand Impersonation
Impersonation of ["telegram"]
Forensic Evidence Collected
Stored evidence from URLScan.io, URLQuery, stored screenshot
Technical Analysis Recorded
Отчет содержит сохраненные технологии или результаты судебно-медицинской экспертизы.
09.08.2026
Complaint Draft Available
Подача не фиксируется. Вы можете создать проект, просмотреть его и самостоятельно отправить в соответствующий орган.
Опубликовано «DestroyList»
29.04.2026
Content Observed Unavailable
Последние сохраненные проверки указывают на то, что сообщаемый контент недоступен; это не устанавливает, кто или что вызвало изменение.
01.05.2026
Время до первой недоступности
С момента обнаружения до первого недоступного наблюдения прошло 33 часов.

Статус в публичных блок-листах

Сохранённый снимок

Аналитика доменов

Домен
URLScan Verdict Анализ завершён score 0 report ↗
Telegram IoCs 4 extracted https://t.me/cormentc2?text=Halo%20… https://t.me/cormentc2?text=Halo%20… https://t.me/cormentc2?text=Halo%20…
Сервер / ASN cloudflare · AS13335 Cloudflare, Inc.
IP Context Cloudflare shared edge origin IP hidden Репутация Edge-IP не связана с этим доменом.
IP-адрес 188.114.97.3 CDN
ГеолокацияCA Toronto, CA
СетьAS13335 · CloudFlare, Inc.
Обратный поиск IPviewdns.info → rapiddns.io →
Исходный IP-адрес скрыт за прокси-сервером CDN. Результаты обратного IP-адреса для граничного адреса содержат несвязанных клиентов; для определения источника требуется пассивный DNS или данные прозрачности сертификатов.
РегистрацияСоздано 28.04.2026 (102d) Expires 28.04.2027
Статус HTTP502 Error
Время до первой недоступности 33h
Что мы учитываем Время, прошедшее с момента первого сохраненного отчета о нарушении до первого наблюдения о недоступности контента. Это не устанавливает причину.
Что содержит каждый отчет Сохраненные записи исходящих отчетов могут ссылаться на доказательства, доступные на данный момент, такие как вердикты поставщиков, регистрационные данные, сведения о хостинге, классификации или снимки экрана. На этой странице не указывается точная доставленная полезная нагрузка, получение, подтверждение или действие получателя.
Технические сведенияDNS, SAN в протоколе SSL, временные метки
Впервые обнаружено29.04.2026
DOM Analysisanalyzed 01.08.2026score 48/1001 brand signal
IoC Extractionscanned 01.08.20260 wallet · 4 Telegram IoCs
Submitted URLhttps://cormentc2.web.id/
Серверы имёнboyd.ns.cloudflare.comchan.ns.cloudflare.com
TLS Fingerprint
TLS Observationvalid from 28.04.2026scanned 29.04.2026
Impersonates
Telegram
Сертификат TLS
Valid transport encryption · Выдан Google Trust Services · valid for 89 days
Технологии · 3 identified
Cloudflare Browser Insights
Analytics RUM

Cloudflare Browser Insights is a tool that measures the performance of websites from the perspective of users.

www.cloudflare.com 100% уверенности
Cloudflare
CDN

Cloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.

www.cloudflare.com 100% уверенности
HTTP/3
Miscellaneous

HTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.

httpwg.org 100% уверенности
Detected via Cloudflare Radar · Wappalyzer engine
Пожаловаться на этот домен Предоставьте доказательства и помогите защитить других

Анализ VirusTotal

4 / Поставщики средств безопасности 91 отметили этот домен
View on VT
Last analyzed First positive detection Previous stored snapshot: 0 detections
alphaMountain.ai
CRDF
Gridinsoft
SOCRadar
Анализ производительности сайта

Google PageSpeed Insights — mobile performance audit of cormentc2.web.id · checked Apr 29, 2026

100
Good
Performance
FCP
0.77s
First Contentful Paint
LCP
0.77s
Largest Contentful Paint
CLS
0
Cumulative Layout Shift
TBT
0ms
Total Blocking Time
SI
1.15s
Speed Index
Powered by Google PageSpeed Insights · Mobile strategy · Scores: 90-100 Good 50-89 Needs Work 0-49 Poor
Доказательства и внешние отчетыIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
If credentials were compromised, report immediately. Do not engage with recovery scammers.

Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.

Европол
Найдите официальный канал отчетности для вашей страны ЕС
National police directory
Остерегайтесь мошенников, предлагающих услуги по восстановлению данных! Преступники могут снова связаться с жертвами, притворяясь следователями, адвокатами или агентами по восстановлению. Не платите авансовые платежи и не делитесь учетными данными. Узнайте больше о мошенничестве при получении компенсаций →

Сообщите об этом в местные органы власти

Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.

Каталог 97 стран
Черновик по шаблону • помощь AI с формулировками включается только с отдельного согласия. Просмотрите и отправьте его самостоятельно
Вставить этот отчетRead-only HTML widget
HTML · IFRAME

Вставить этот отчет

Разместите эту информацию об угрозах на своём сайте или в блоге

embed.html
<iframe
  src="https://phishdestroy.io/ru/embed/domain/cormentc2.web.id"
  title="PhishDestroy threat report for cormentc2.web.id"
  width="100%" height="320"
  loading="lazy"
  referrerpolicy="no-referrer"
  sandbox="allow-same-origin allow-popups allow-popups-to-escape-sandbox"
  style="border:0;border-radius:12px;max-width:100%"
></iframe>