loomizbk[.]com[.]mazcapitals[.]com
“403 Forbidden”
loomizbk.com.mazcapitals.com — Непроверенный. Сводка доказательств: VirusTotal 10/91 (BitDefender, Chong Lua Dao, CRDF, CyRadar, ESET); PhishDestroy score 88/100. Регистратор: Global Domain Group.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
This domain, loomizbk.com.mazcapitals.com, is currently flagged as a high‑risk generic phishing site. Analysis of public threat feeds shows that PhishDestroy has already added the domain to its blocklist, and at least one additional security blocklist also lists it. VirusTotal reports that 10 out of 91 scanned security vendors have identified the domain as malicious, confirming its reputation as a phishing resource. The domain resolves to name servers ns17.asurahosting.com, ns17.my-control-panel.com and ns18.asurahosting.com, indicating that the infrastructure is hosted by Asura Hosting services.
An HTTP request to the domain returns a 302 redirect, a common technique used to forward victims to credential‑harvesting pages or to mask the final landing site. Registration data reveals that the domain was acquired through Global Domain Group LLC, a registrar that is frequently observed in malicious registrations. The domain remains active as of the report date, July 27 2026, and its risk level is classified as high. Defenders should ingest the domain into network and endpoint detection rules, enforce DNS‑based blocking, and ensure that any web‑proxy or URL filtering solutions reference the latest blocklists that contain this indicator.
Because the domain is already flagged by multiple vendors, adding it to existing threat‑intel feeds will reduce the likelihood of successful phishing attempts. Continuous monitoring of the associated name servers and the parent domain mazcapitals.com is advisable, as adversaries often reuse infrastructure for additional campaigns. In environments where credential exfiltration is a concern, organizations should scrutinize outbound connections to the IP addresses resolved from the listed name servers and consider applying URL‑allow‑list policies that exclude this subdomain.
Данные сетевой безопасности
Процесс реагирования на угрозы
Статус в публичных блок-листах
Аналитика доменов
Технические сведенияDNS, SAN в протоколе SSL, временные метки
ICANN OVERSIGHT
Registration: mazcapitals.com
Аккредитация и контекст RAA
Аккредитация и контекст RAA
Registrar accreditation and DNS abuse obligations
For the registrable domain mazcapitals.com behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Анализ VirusTotal
Анализ производительности сайта
Google PageSpeed Insights — mobile performance audit of loomizbk.com.mazcapitals.com · checked Jul 27, 2026
Анализ конфигурации сайта
Доказательства и внешние отчеты
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание