whale-ai[.]cfd
“Whale AI”
whale-ai.cfd — Контент недоступен (HTTP 502). Олицетворение бренда: Telegram; Тип мошенничества: Brand Impersonation. Сводка доказательств: VirusTotal 3/93 (Fortinet, Gridinsoft, Seclookup); Spamhaus DBL_PHISH; 1 external blocklist match (ScamSniffer); PhishDestroy score 65/100.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
The domain whale-ai.cfd was registered on February 21, 2026 and is currently taken offline. Infrastructure analysis shows it resolves to the IP address 172.67.154.91, which belongs to AS13335 Cloudflare, Inc. and is geolocated in the United States. The SSL certificate presented for the site is identified as WE1, indicating a standard TLS termination provided by the hosting provider. The page title returned by the server is "Whale AI," and the domain is classified under the scam type "Brand Impersonation" with a specific target of the Telegram brand.
Threat intelligence sources list the domain on two security blocklists, PhishDestroy and ScamSniffer, confirming its malicious reputation. VirusTotal scans have resulted in three of ninety‑three security vendors flagging the domain, reinforcing the presence of malicious indicators. Additionally, Gridinsoft assigns a trust score of 0 out of 100, reflecting an extremely low confidence in the domain’s legitimacy. While the site is currently offline, the combination of blocklist listings, vendor detections, a zero trust score, and the explicit brand impersonation claim provide substantive evidence of malicious intent.
Uncertainty remains regarding the exact content that was served before takedown, as no visual or functional analysis is available beyond the page title. Defenders should immediately block any outbound or inbound traffic to 172.67.154.91 and add whale-ai.cfd to URL filtering policies. Security operations teams ought to monitor for new domains that resolve to the same Cloudflare IP range and update detection signatures to capture the "Whale AI" page title pattern. Continuous review of threat intel feeds for additional detections related to this domain is recommended to maintain situational awareness.
Процесс реагирования на угрозы
Статус в публичных блок-листах
Сохранённый снимок
Аналитика доменов
Технические сведенияDNS, SAN в протоколе SSL, временные метки
ЗОНА SHORTDOT · ПУБЛИЧНЫЕ ДОКАЗАТЕЛЬСТВА
.cfd
ShortDot zone evidence
ShortDot zone evidence
The linked repository preserves daily zone observations across seven ShortDot-operated TLDs, including registration volume and abuse-related indicators. This registry context is supporting background and is not an independent detection for the domain in this report.
Криминалистическая аналитика
Анализ VirusTotal
Доказательства и внешние отчеты
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание