financemoneycare.com.habithousecozy.com
“Finance Money Care”
financemoneycare.com.habithousecozy.com — Контент недоступен. Олицетворение бренда: Unknown; Тип мошенничества: Generic Phishing. Сводка доказательств: VirusTotal 6/91 (ADMINUSLabs, alphaMountain.ai, Forcepoint ThreatSeeker, Fortinet, Gridinsoft); URLQuery 1 alert; Spamhaus DBL_PHISH; PhishDestroy score 85/100. Регистратор: Dynadot.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
Сводка доказательств
This domain, financemoneycare.com.habithousecozy.com, is flagged as a high-risk credential phishing resource targeting users under the guise of a financial service portal. Analysis of the page title, 'Finance Money Care,' suggests an attempt to impersonate legitimate financial institutions or money management platforms, likely aiming to harvest login credentials, personal identification details, or financial account information. No specific drainer kit signatures have been confirmed at this stage, though the infrastructure aligns with common phishing toolkits used in credential theft campaigns. Infrastructure analysis reveals the domain was registered on February 25, 2026, through Dynadot Inc, a registrar frequently observed in phishing operations. It resolves to the IP address 194.36.191.196, hosted on AS60117 (Host Sailor Ltd) in the Netherlands. The domain is secured with a Let's Encrypt SSL certificate (R12), a tactic often employed to lend false legitimacy to malicious sites. Detection metrics indicate a VirusTotal score of 3/95, with only one security blocklist currently flagging the domain. No entries were found in Google Safe Browsing at the time of assessment, though this does not preclude malicious intent. The domain remains active and continues to host phishing content, posing a persistent risk to users who may encounter it through spam emails, compromised advertisements, or social engineering tactics. Response actions should include immediate blacklisting by network security providers, takedown requests to the hosting provider, and registrar-level suspension. Despite low detection counts, the domain's recent creation date, use of a high-reputation registrar, and targeted financial branding elevate its risk profile. Users are advised to avoid interaction, verify financial service URLs through official channels, and report suspicious links to relevant security teams for further mitigation.
Данные сетевой безопасности
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Cloudflare DNS | leostop.com |
malicious | Sinkholed |
Forensic History & Detection Timeline
-
Domain Status Transition Aug 9, 2026 · 00:15 UTCDomain state transitioned from dead to alive.
-
Domain Status Transition Aug 8, 2026 · 00:29 UTCDomain state transitioned from alive to dead.
Процесс реагирования на угрозы
Статус в публичных блок-листах
Evasion analysis
Cloaking & traffic-distribution check
Stored crawler-versus-browser observations for this host, plus a live fingerprint check for Keitaro-style traffic distribution systems.
- Stored cloaking flag
- Not observed
- Оценка маскировки
- 0/6
- Last cloaking scan
Scanner note: dns_error: raw=dns_error; via=local_dns_prefilter
Технологии · 6 identified
Анализ VirusTotal
Доказательства и внешние отчеты
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание