prvinote[.]cc
Проверка домена prvinote.cc на фишинг и безопасность
“BurnNote - Vanishing Encrypted Messages”
prvinote.cc — Контент недоступен (HTTP 502). Сводка доказательств: VirusTotal 5/95 (alphaMountain.ai, CyRadar, Forcepoint ThreatSeeker, Fortinet, SOCRadar); Spamhaus DBL_PHISH; PhishDestroy score 65/100. Регистратор: NiceNIC.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
Analysis of prvinote.cc, observed on July 25 2026, shows that the domain was registered on February 21 2026 through NiceNIC International Group Co., Limited. The authoritative name servers are autumn.ns.cloudflare.com and dane.ns.cloudflare.com, indicating use of Cloudflare’s DNS service. DNS resolution points to IP address 104.21.80.46, which belongs to AS13335 Cloudflare, Inc. and is geolocated to the United States. The site presented the page title “BurnNote - Vanishing Encrypted Messages” and employed front‑end libraries such as Bootstrap and jsDelivr, while traffic was served over Cloudflare with HTTP/3 enabled. No TLS certificate was detected, implying that HTTPS was not configured at the time of observation.
Reputation checks reveal a Gridinsoft trust score of 0 out of 100. VirusTotal recorded five positive detections out of ninety‑five scanned scanners, and the domain appears on three public blocklists. Additional blocking services, including PhishDestroy, MetaMask, and SEAL, have listed the domain as malicious. The current operational status is offline, and the site is no longer reachable. The collected evidence confirms that prvinote.cc was actively used for a generic phishing campaign targeting users with a vanishing encrypted message service.
While the page content has not been captured, the combination of a low trust score, multiple vendor detections, and inclusion on specialized blocklists strongly indicates malicious intent. Uncertainty remains regarding the exact phishing payload, victim interaction flow, and whether any credential harvest occurred before the takedown. Defenders should continue to block the domain at network perimeter, update DNS filtering policies to include the observed IP range, and monitor for any resurgence of similar Cloudflare‑hosted infrastructure. Ongoing vigilance is advised, especially for users of services referenced by the blocking lists, to prevent potential credential compromise.
Данные сетевой безопасности Registrar context
Процесс реагирования на угрозы
Статус в публичных блок-листах
Latest Classified Outcome 2026-08-08 04:13:41 UTC
Технологии · 4 identified
Popular CSS framework for responsive, mobile-first web development.
Free public CDN for open-source projects, serving files from npm and GitHub.
Web infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
Анализ VirusTotal
Архивные доказательства
Доказательства и внешние отчеты
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание