fifaworldcup2026philadelphiahotels[.]com
fifaworldcup2026philadelphiahotels.com — Непроверенный. Тип мошенничества: Generic Phishing. Сводка доказательств: VirusTotal 11/91 (alphaMountain.ai, ArcSight Threat Intelligence, BitDefender, CRDF, Forcepoint ThreatSeeker); PhishDestroy score 88/100. Регистратор: GoDaddy.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
This domain, fifaworldcup2026philadelphiahotels.com, is identified as a phishing infrastructure designed to deceive users seeking accommodations for the 2026 FIFA World Cup in Philadelphia. Analysis indicates the site mimics legitimate hotel booking platforms, likely harvesting personal and financial data under the guise of event-related reservations. The fraudulent nature of this domain aligns with common phishing tactics targeting high-profile sporting events, where demand for lodging creates opportunities for credential theft and financial fraud. Infrastructure analysis reveals multiple technical indicators confirming malicious intent. The domain was registered on June 12, 2026, through a major registrar, and resolves to the IP address 15.197.148.33. It appears on one security blocklist and is flagged by 6 out of 95 security vendors on a malware analysis platform. Additionally, the domain is referenced in four threat intelligence pulses, further corroborating its association with phishing campaigns. The SSL certificate, issued by a widely used certificate authority, does not mitigate the risk, as phishing sites frequently employ valid certificates to appear legitimate. Users who visited fifaworldcup2026philadelphiahotels.com should take immediate action to mitigate potential compromise. Disconnect the device from the network and scan for malware using updated security tools. Reset passwords for any accounts accessed after visiting the site, prioritizing financial and email credentials. Monitor bank statements and credit reports for unauthorized transactions, and report the incident to relevant fraud prevention authorities. If payment information was entered, contact the financial institution to block or reverse any fraudulent charges. Exercise heightened caution with unsolicited communications related to the 2026 FIFA World Cup, as additional phishing domains may emerge.
Процесс реагирования на угрозы
Статус в публичных блок-листах
Сохранённый снимок
Аналитика доменов
Технические сведенияDNS, SAN в протоколе SSL, временные метки
ICANN OVERSIGHT
Аккредитация и контекст RAA
Аккредитация и контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Технологии · 8 identified
Node.js is an open-source, cross-platform, JavaScript runtime environment that executes JavaScript code outside a web browser.
nodejs.org 100% уверенностиBootstrap is a free and open-source CSS framework directed at responsive, mobile-first front-end web development. It contains CSS and JavaScript-based design templates for typography, forms, buttons, navigation, and other interface components.
getbootstrap.com 100% уверенностиNginx is a web server that can also be used as a reverse proxy, load balancer, mail proxy and HTTP cache.
nginx.org 100% уверенностиOpenResty is a web platform based on nginx which can run Lua scripts using its LuaJIT engine.
openresty.org 100% уверенностиExpress is a web application framework for Node.js, released as free and open-source software under the MIT License. It is designed for building web applications and APIs.
expressjs.com 100% уверенностиApache Traffic Server is an open-source caching and proxying server that serves as an HTTP/1.1 and HTTP/2 reverse proxy with caching capabilities, load balancing, request routing, SSL termination, and support for advanced HTTP features.
trafficserver.apache.org 100% уверенностиTrustpilot is a Danish consumer review website which provide embed stand-alone applications in your website to show your most recent reviews, TrustScore, and star ratings.
business.trustpilot.com 100% уверенностиHTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org 100% уверенностиАнализ VirusTotal
Анализ конфигурации сайта
Доказательства и внешние отчеты
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание