railway-consultation-besides-techrepublic[.]trycloudflare[.]com
“Sign in - Professional Email”
railway-consultation-besides-techrepublic.trycloudflare.com — Контент недоступен (HTTP 502). Олицетворение бренда: Networksolutions; Тип мошенничества: Credential Phishing. Сводка доказательств: VirusTotal 13/94 (alphaMountain.ai, BitDefender, CRDF, CyRadar, Emsisoft); URLQuery 3 alerts; URLScan malicious verdict; Spamhaus DBL_PHISH; PhishDestroy score 89/100. Регистратор: Cloudflare.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
Analysis of the domain railway-consultation-besides-techrepublic.trycloudflare.com indicates it was used for credential phishing targeting professional email accounts. The site was registered on March 06, 2026 through Cloudflare, Inc., and resolves to the Cloudflare edge address 104.16.230.132, which is associated with ASN 13335 in the United States. The SSL certificate presented is issued by Google Trust Services under the WE1 root, confirming that TLS termination is performed by Cloudflare’s infrastructure.
The page title observed during the brief live period was "Sign in - Professional Email," matching the declared scam type of credential phishing. VirusTotal scans recorded 13 positive detections out of 94 security vendors, and the domain appears on a single public blocklist, where it has been listed by PhishDestroy. Nameserver records point to kevin.ns.cloudflare.com and marjory.ns.cloudflare.com, both standard Cloudflare resolvers.
The site has since been taken offline, but the underlying hosting and certificate remain active, allowing potential re‑use of the same infrastructure. Defenders should continue to block the IP 104.16.230.132 at perimeter devices, add the domain to internal phishing blocklists, and monitor Cloudflare‑associated subdomains for rapid re‑deployment. Ongoing vigilance is recommended, especially for organizations that rely on professional email services, to detect any future attempts that may reuse the same page title or certificate fingerprint.
Данные сетевой безопасности
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DigiCert UltraDNS | railway-consultation-besides-techrepublic.trycloudflare.com |
malicious | Sinkholed |
| DNS4EU | railway-consultation-besides-techrepublic.trycloudflare.com |
malicious | Sinkholed |
| OpenDNS | railway-consultation-besides-techrepublic.trycloudflare.com |
phishing | Phishing Block |
Процесс реагирования на угрозы
Статус в публичных блок-листах
Анализ VirusTotal
Архивные доказательства
Доказательства и внешние отчеты
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание