www-firstharlzon[.]top
“Log In”
www-firstharlzon.top — Контент недоступен (HTTP 502). Олицетворение бренда: Firsthorizon; Тип мошенничества: Credential Phishing. Сводка доказательств: VirusTotal 20/93 (Criminal IP, alphaMountain.ai, BitDefender, CRDF, CyRadar); URLQuery 1 alert; URLScan malicious verdict; Spamhaus DBL_PHISH; 3 external blocklist matches (Polkadot, Enkrypt, Codeesura); PhishDestroy score 95/100. Регистратор: 耐思尼克国际集团有限公司.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
This domain, www-firstharlzon.top, has been identified as a credential theft phishing site designed to harvest user login credentials. Analysis of the page title, 'Log In,' and the domain structure suggests an attempt to impersonate a legitimate authentication portal, likely targeting unsuspecting users through deceptive login prompts. No direct evidence of a crypto drainer kit or brand-specific impersonation (e.g., financial institutions or e-commerce) was observed, but the generic login interface aligns with broad credential harvesting tactics. Technical indicators confirm the domain's malicious nature. The domain resolves to the IP address 144.31.244.50, hosted under AS213877 (U1 DIGITAL SERVICES LTD) in Germany. It was registered on December 16, 2025, through the registrar 耐思尼克国际集团有限公司, a provider frequently associated with high-risk domains. VirusTotal detection metrics show 20 out of 95 security vendors flagging the domain as malicious. The domain appears on four security blocklists, including entries in PhishDestroy, Polkadot, Enkrypt, and Codeesura. The SSL certificate, classified as R13, further indicates low trust, as this type of certificate is often used in short-lived phishing campaigns to mimic legitimacy without proper validation. As of the latest assessment, www-firstharlzon.top has been taken offline, reducing immediate exposure risk. However, the infrastructure analysis reveals patterns consistent with disposable phishing domains, including the use of a recently registered domain and a hosting provider known for lax abuse enforcement. Organizations and individuals are advised to monitor for similar domains registered through the same registrar or resolving to the identified IP range. Users who may have interacted with the site should reset credentials for any accounts accessed during the exposure window and enable multi-factor authentication where available. Proactive blocking of the domain and its associated IP at the network level is recommended to prevent residual access attempts.
Данные сетевой безопасности
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DNS0 Zero | www-firstharlzon.top |
malicious | Sinkholed |
Процесс реагирования на угрозы
Статус в публичных блок-листах
Сохранённый снимок
Аналитика доменов
Технические сведенияDNS, SAN в протоколе SSL, временные метки
ICANN OVERSIGHT
Аккредитация и контекст RAA
Аккредитация и контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Анализ VirusTotal
Доказательства и внешние отчеты
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание