lalvice[.]live
“Messenger”
This domain, lalvice.live, is actively engaged in credential harvesting phishing operations specifically targeting users of the Messenger platform. Analysis indicates the site mimics legitimate Messenger login interfaces to deceive visitors into submitting their account credentials, which are then captured by threat actors for unauthorized access, account takeovers, or further malicious activities such as financial fraud or identity theft. The infrastructure is designed to exploit trust in the Messenger brand, leveraging social engineering tactics to maximize victim engagement. Infrastructure analysis reveals multiple high-confidence indicators of malicious activity. The domain was registered on June 24, 2026, through NICENIC INTERNATIONAL GROUP CO., LIMITED, a registrar frequently associated with high-risk domains. VirusTotal reports that 13 out of 95 security vendors have flagged lalvice.live as malicious, while it also appears on one security blocklist. The domain resolves to the IP address 172.67.218.213, which has been linked to other phishing campaigns in recent threat intelligence pulses. Additionally, the domain has been identified in one AlienVault OTX threat intelligence report, further corroborating its malicious nature. Users who have visited lalvice.live or entered credentials on the site should take immediate action to mitigate potential risks. First, change passwords for any accounts that may have been exposed, prioritizing Messenger and any accounts where the same credentials were reused. Enable multi-factor authentication (MFA) on all critical accounts to prevent unauthorized access. Monitor accounts for suspicious activity, such as unrecognized logins or messages sent without consent. If financial or personally identifiable information was submitted, consider placing a fraud alert on credit reports and reviewing financial statements for unauthorized transactions. Finally, report the domain to relevant security teams or platforms to aid in broader threat mitigation efforts.
Gönderilen rapor kaydı
Gönderilen kanıt anlık görüntüsü
- Gönderildi
- Kayıt defteri kayıtları
- 1
- Vaka kimliği
PD-20260628-9F86B6- PDF belgesi
- PDF kanıtı
Kanıtın tam metni
Illegal Activities: Active phishing operation targeting victims
Fraud & Deception: Impersonation of legitimate services
Identity Theft: Collection of credentials under false pretenses
Applicable Laws (Unknown):
International Anti-Cybercrime Regulations
Budapest Convention on Cybercrime
Universal Fraud Prevention Laws
Phishing activities violate international cybercrime conventions and Unknown's domestic fraud laws.
Action Required: This evidence-backed report demonstrates clear violations requiring suspension per your policies. Continued hosting exposes your organization to regulatory scrutiny and potential legal liability.
Ağ Güvenliği İstihbaratı Registrar context
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| OpenDNS | lalvice.live |
phishing | Phishing Block |
| Cloudflare DNS | lalvice.live |
malicious | Sinkholed |
| DNS4EU | lalvice.live |
malicious | Sinkholed |
Tehdit Müdahale Pipeline
Engelleme listesi kapsamı
10 kaynak · 09.08.2026 tarihinde eşitlendi
Kaydedilmiş sonuç kanıtı
Sonuç ve kaldırma ilişkilendirmesi
- Sonuç
held- Neden
registrar_client_hold- Aktör
- NICENIC INTERNATIONAL GROUP CO., LIMITED
- Mekanizma
client_hold- Güven
- 95%
Kayıt kuruluşu işlemi
NICENIC INTERNATIONAL GROUP CO., LIMITED IANA 3765
İlişkilendirme kanıtı:
Tahmini erişilememe
Belirsizlik aralığı: ±657.46 h Zaman hassasiyeti:low Tespit zaman çizelgesi
Kaydedilmiş gözlemler kronolojik sıradadır.
-
VirusTotal
VirusTotal: 13 → 13
-
Erişilebilirlik
Erişilebilirlik: ilk kez dns_inactive olarak gözlemlendi
f93a11f87e4d -
Erişilebilirlik
Erişilebilirlik: dns_inactive → unknown
b7a0c4d1c668 -
Erişilebilirlik
Erişilebilirlik: unknown → dns_inactive
02b66c6123bf -
Erişilebilirlik
Erişilebilirlik: dns_inactive → unknown
a7251c436477 -
Erişilebilirlik
Erişilebilirlik: unknown → dns_inactive
6dfe9145995c -
Erişilebilirlik
Erişilebilirlik: dns_inactive → unknown
4e3e5f389fd1 -
Erişilebilirlik
Erişilebilirlik: unknown → held
6d21cdbf3cd5 -
Erişilebilirlik
Erişilebilirlik: held → unknown
0f5ce1f06d15 -
Erişilebilirlik
Erişilebilirlik: unknown → dns_inactive
d0b7046e8c2f
Tümünü göster (1)
-
Erişilebilirlik
Erişilebilirlik: dns_inactive → held
4ccc31fc98a7
Kaydedilen görüntü
Etki Alanı Analizi
Teknik ayrıntılarDNS, SSL SAN’ları, zaman damgaları
ICANN OVERSIGHT
Akreditasyon ve RAA bağlamı
Akreditasyon ve RAA bağlamı
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
VirusTotal Analizi
Bu Siteden Etkilendiniz mi?
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.
Herhangi Bir Alan Adını Kontrol Et
Saklanan engelleme listesi, WHOIS, DNS ve genel tarama kanıtlarını kullanarak tehdit analizi
Şimdi TaraOltalama Olayını Bildir
Şüpheli alan adlarını tehdit veritabanımıza bildirin — topluluğu koruyun
BildirCanlı Tehdit Akışı
Son kimlik avı raporları ve gözlemlenen kullanılabilirlik değişiklikleri
İzleGelişmelerden Haberdar Olun, Güvende Kalın
Canlı tehditleri izleyin veya bunun yanlış bir uyarı olduğunu düşünüyorsanız bu kayda itiraz edin