cs880817-wordpress-f5a04[.]tw1[.]ru
“Домен припаркован в Timeweb”
cs880817-wordpress-f5a04.tw1.ru — Непроверенный. Олицетворение бренда: Wordpress; Тип мошенничества: Brand Impersonation. Сводка доказательств: VirusTotal 14/91 (ADMINUSLabs, alphaMountain.ai, BitDefender, CyRadar, ESET); Google Safe Browsing flagged; CF Radar malicious; PhishDestroy score 97/100. Регистратор: TW-Cloud (ASN: 9123).
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
This domain, cs880817-wordpress-f5a04.tw1.ru, is actively flagged as a high-risk brand impersonation threat targeting WordPress. Analysis indicates the domain is registered through TW-Cloud (ASN 9123) and currently resolves to the IPv6 address 2a03:6f00:1::5c35:6069. The page title, 'Домен припаркован в Timeweb,' suggests it may be hosted on a parked domain service, though the exact content remains unanalyzed. Security vendors have detected malicious indicators, with 12 out of 95 engines on VirusTotal flagging the domain, and it appears on two security blocklists, including PhishDestroy and PhishingDB. The domain is explicitly categorized as engaging in social engineering, as confirmed by Google Safe Browsing. Its Gridinsoft trust score of 0/100 and Scamadviser trust score of 1/100 further corroborate its high-risk classification. The SSL certificate is issued by GlobalSign nv-sa, which does not mitigate the underlying threat but may lend a superficial appearance of legitimacy. No specific phishing kit or payload has been identified in the available data, leaving the exact attack vector uncertain. Defenders should treat this domain as an active threat. Immediate action includes blocking the domain and its resolving IP at the network perimeter, as well as monitoring for any internal connections to it. Given the domain's association with brand impersonation and social engineering, user awareness training may be warranted to prevent potential credential harvesting or malware distribution. The domain remains active as of July 12, 2026, and should be prioritized for further investigation if any internal systems have interacted with it. No evidence suggests this is part of a larger campaign, but its registration through a known hosting provider warrants scrutiny of related infrastructure.
Сигналы безопасности
Данные сетевой безопасности
Процесс реагирования на угрозы
Статус в публичных блок-листах
Анализ VirusTotal
Архивные доказательства
Доказательства и внешние отчеты
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание