post[.]ch-zahlungssystem[.]sale
post.ch-zahlungssystem.sale — Контент недоступен (HTTP 502). Сводка доказательств: VirusTotal 15/93 (ADMINUSLabs, Criminal IP, BitDefender, CRDF, CyRadar); Spamhaus DBL_PHISH; PhishDestroy score 95/100.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
The domain post.ch-zahlungssystem.sale was registered on February 21, 2026 and currently resolves to the IPv4 address 172.67.174.247, which is owned by Cloudflare, Inc. (AS13335) and geolocated to the United States. The domain’s SSL certificate is identified as WE1, indicating a valid TLS layer but offering no additional trust signals. VirusTotal has recorded 15 positive detections out of 93 scanned security vendors, confirming that multiple independent scanners flag the domain as malicious. It appears on a single public blocklist and is actively blocked by the PhishDestroy service, reinforcing the consensus that the domain is being used for phishing.
The threat classification supplied is “generic phishing,” and the risk level is elevated. The site has been taken offline, as indicated by the status flag, and no HTTP response body or page title is available for further analysis. Defenders should add the IP address 172.67.174.247 to network‑level deny lists only after confirming that legitimate services are not hosted on the same address, recognizing that Cloudflare’s shared infrastructure may host unrelated traffic. The domain name itself should be added to URL filtering and email security policies to block any future attempts to reference it.
Continuous monitoring of the associated IP and ASN for new malicious domains is advised, as threat actors frequently reuse Cloudflare edge nodes. Because the domain is already flagged by VirusTotal and PhishDestroy, automated blocklist feeds will likely capture future re‑registrations, but manual rule updates provide an additional safety net. Until further forensic evidence, such as page content or credential harvesting behavior, becomes available, the recommendation is to treat post.ch‑zahlungssystem.sale as a high‑confidence phishing indicator and enforce strict deny controls across perimeter defenses.
Процесс реагирования на угрозы
Статус в публичных блок-листах
Криминалистическая аналитика
Анализ VirusTotal
Доказательства и внешние отчеты
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание