creteportway[.]live
“Crête Portway | Official Platform for AI Assisted Trading”
creteportway.live — Последний известный активный (HTTP 200). Тип мошенничества: Brand Impersonation. Сводка доказательств: VirusTotal 17/91 (alphaMountain.ai, Bfore.Ai PreCrime, BitDefender, Cluster25, CRDF); Spamhaus DBL_PHISH; PhishDestroy score 100/100. Регистратор: NiceNIC.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
The domain creteportway.live was registered on May 15, 2026 through NICENIC INTERNATIONAL GROUP CO., LIMITED and currently resolves to the Cloudflare address 172.67.212.81 located in Canada. An HTTPS service is presented using a Let's Encrypt certificate (E8) and the web server returns HTTP status 200. The page title presented to visitors reads 'Crête Portway | Official Platform for AI Assisted Trading', suggesting an attempt to masquerade as a legitimate financial service. Infrastructure analysis shows the domain is served entirely from Cloudflare's network, as indicated by the authoritative nameservers adi.ns.cloudflare.com and leland.ns.cloudflare.com. The Cloudflare edge location masks the true origin server, a common tactic for phishing infrastructure to evade takedown and to benefit from Cloudflare's built‑in DDoS protection. The SSL certificate is valid and automatically renewed, which further reduces visual cues of malicious intent. Threat intelligence corroborates malicious intent: the domain appears on a single security blocklist and has been listed by PhishDestroy as a phishing site. VirusTotal scans have flagged the domain in 3 out of 95 security vendors, and Gridinsoft assigns a trust score of 0 out of 100, indicating extreme suspicion. AlienVault OTX references the domain in one threat pulse, and the same indicator was observed in a recent campaign targeting users of AI‑assisted trading platforms. Defenders should treat creteportway.live as a high‑risk phishing vector. Immediate network‑level blocking of the domain and its associated IP address is advised, along with monitoring of outbound DNS queries for the listed nameservers. Because the underlying hosting is abstracted behind Cloudflare, takedown attempts may require coordination with the registrar. Continuous observation is needed to detect any content changes that could expand the phishing campaign.
Данные сетевой безопасности Registrar context
Процесс реагирования на угрозы
Статус в публичных блок-листах
Аналитика доменов
Технические сведенияDNS, SAN в протоколе SSL, временные метки
ICANN OVERSIGHT
Аккредитация и контекст RAA
Аккредитация и контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Latest Classified Outcome 2026-08-14 02:40:46 UTC
Анализ VirusTotal
Анализ конфигурации сайта
Доказательства и внешние отчеты
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание