ctr-citrea[.]xyz
Сводка доказательств
Analysis of ctr-citrea.xyz indicates an active, elevated‑risk phishing infrastructure. The domain was registered on May 22, 2026 through Porkbun LLC, a registrar frequently used by malicious actors. VirusTotal scans show that five of ninety‑one security vendors flagged the domain, providing a modest but notable detection signal.
Independent security blocklists have listed the domain three times, and it is currently blocked by PhishDestroy, MetaMask, and SEAL, reinforcing the consensus that the site is being used for malicious credential harvesting. The threat type is classified as generic phishing, and the operational status remains active as of the report date, July 29, 2026. No publicly available information on hosting IP, ASN, geographic location, SSL certificate details, or HTTP response codes was supplied, leaving those vectors unverified.
Consequently, defenders should prioritize immediate containment: add ctr-citrea.xyz to DNS and proxy blocklists, enforce network‑level deny rules, and monitor for any outbound connections to the domain. Continuous re‑evaluation is advised, as additional intelligence such as page content, certificate fingerprints, or hosting infrastructure may emerge. Until further artifacts are disclosed, the domain should be treated as a confirmed phishing source and mitigated accordingly.
Data Coverage
Данные сетевой безопасности
Процесс реагирования на угрозы
Проверка по блок-листам
10 внешних источников под наблюдением · снимок от 13.08.2026
8 внешних источников под наблюдением Совпадений нет
Хронология обнаружения
-
Статус домена
Доступен → Недоступен
Аналитика доменов
Технические деталиDNS, имена TLS и временные метки
ICANN OVERSIGHT
Аккредитация и контекст RAA
Аккредитация и контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Анализ VirusTotal
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание