1217[.]cc
1217.cc için kimlik avı ve güvenlik kontrolü
“Clock error”
1217.cc — Bilinen son aktif (HTTP 301). Kanıt özeti: VT 12/93 (ADMINUSLabs, alphaMountain.ai, BitDefender, CRDF, CyRadar); URLQuery 3 alerts; URLScan no malicious verdict; GSB no flag; BL 1 (Enkrypt); PD 100/100. Kayıt kuruluşu: GoDaddy.
Özgün adli kaydı korumak için aşağıdaki ayrıntılı PhishDestroy AI analizi İngilizce bırakılmıştır.
1217.cc entered the PhishDestroy evidence set on Feb 26, 2026. The assembled evidence scores 100/100 (critical).
Three independent sources are positive: VirusTotal, Enkrypt, and URLQuery. VirusTotal recorded 12 detections among 93 engines: ADMINUSLabs, alphaMountain.ai, BitDefender, CRDF, CyRadar, ESET, Forcepoint ThreatSeeker, G-Data, Kaspersky, Lionic, Seclookup, Sophos on Jul 10, 2026 at 15:05 UTC. Enkrypt listed the hostname in the external-blocklist snapshot on Aug 7, 2026 at 18:20 UTC. URLQuery recorded 3 threat-system alerts on Nov 9, 2025 at 23:10 UTC. The evidence is not unanimous. AlienVault OTX listed 1 community pulse reference (not vendor detections) on Mar 1, 2026 at 01:07 UTC. Google Safe Browsing returned no flag on Mar 2, 2026 at 20:53 UTC. URLScan completed without a malicious verdict (score 0).
HTTP 301 was recorded on Aug 7, 2026 at 10:04 UTC. Registration records for the domain list GoDaddy.com, LLC as the registrar and Feb 21, 2026 as the creation date. Registration preceded first observation by 5 days. At collection time, the hostname resolved to 2405:1c0:6611:678:b7fb:f75d:91:118 on AS55547 (WOODSNET-PH Unit D,E,F,G 28th Floor, PH). The associated network metadata labels the endpoint as AS55547 WOODSNET-PH in Taipei, TW. The stored server header is CK6u06Vu4. Captured page title: “Clock error”. DOM analysis completed on Jul 9, 2026 at 02:21 UTC; stored DOM score 93/100. The evidence archive retains 3 visual captures from PhishDestroy, URLScan, and URLQuery. IoC extraction completed on Jul 29, 2026 at 02:28 UTC; stored 0 format-validated wallet addresses and 0 Telegram indicators. TLS metadata lists sslTrus / sslTrus (RSA) DV CA as the certificate issuer; checked Mar 15, 2026 at 08:10 UTC.
No target brand has been confirmed from stored page content; hostname wording alone is not treated as brand evidence. Taken together, the page content and independent findings support classifying this hostname as phishing. The stored record does not establish the post-click interaction, and it does not claim a confirmed wallet-draining transaction or credential submission.
Ağ Güvenliği İstihbaratı
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Hagezi Threat Feed | www12120719.ats.elegancepath.online |
malicious | Sinkholed |
| Hagezi Threat Feed | 1217.cc |
malicious | Sinkholed |
| CIRA Canadian Shield DNS | 1217.cc |
malicious | Sinkholed |
Tehdit Müdahale Pipeline
Genel Engelleme Listesi Durumu
VirusTotal Analizi
Kanıtlar ve Dış Raporlar
Bu Siteden Etkilendiniz mi?
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.
Herhangi Bir Alan Adını Kontrol Et
Saklanan engelleme listesi, WHOIS, DNS ve genel tarama kanıtlarını kullanarak tehdit analizi
Şimdi TaraOltalama Olayını Bildir
Şüpheli alan adlarını tehdit veritabanımıza bildirin — topluluğu koruyun
BildirCanlı Tehdit Akışı
Son kimlik avı raporları ve gözlemlenen kullanılabilirlik değişiklikleri
İzleGelişmelerden Haberdar Olun, Güvende Kalın
Canlı tehditleri izleyin veya bunun yanlış bir uyarı olduğunu düşünüyorsanız bu kayda itiraz edin