pc[.]cflgroupltd[.]cc
“CFL Group”
Kanıt özeti
This domain, pc.cflgroupltd.cc, is identified as a fraudulent login portal designed to impersonate CFL Group, a legitimate corporate entity. Analysis confirms the domain was actively engaged in credential harvesting, a specific phishing tactic targeting corporate or financial sector employees. As of the latest verification, the domain has been taken offline, though residual risks may persist due to cached DNS records or secondary distribution channels. Infrastructure analysis reveals the domain was flagged by 12 of 95 security vendors on VirusTotal, indicating a high-confidence malicious classification. It was registered through Gname.com Pte. Ltd. on August 27, 2024, and resolved to the IP address 172.67.154.251, hosted on Cloudflare’s network (AS13335). The domain appeared on three security blocklists, including PhishDestroy and MetaMask, further corroborating its malicious intent. The SSL certificate was issued by Google Trust Services (WE1), a common tactic to lend false legitimacy to phishing pages. The page title, "CFL Group," was explicitly crafted to deceive users into believing they were accessing an official corporate portal. Current status confirms the domain has been disabled, though organizations should remain vigilant for related indicators of compromise. Security teams are advised to block the domain and its associated IP (172.67.154.251) at the perimeter, update endpoint detection rules to include the domain and SSL certificate thumbprint, and conduct retrospective log analysis for any prior connections. Employees should be briefed on recognizing impersonation tactics, particularly those mimicking corporate login portals. If credentials were entered on this domain, immediate password resets and multi-factor authentication enforcement are recommended for all affected accounts.
Data Coverage
Ağ Güvenliği İstihbaratı
Tehdit Müdahale Pipeline
Engelleme listesi kapsamı
10 izlenen harici kaynak · kayıtlı anlık görüntü 11.08.2026
Tespit zaman çizelgesi
-
VirusTotal
0 → 12
Topluluk raporları
1 topluluk üyesi tarafından bildirildi; ilk görülme 10.03.2026
- Kayıtlı raporlar
- 1
- Bildirilen benzersiz URL’ler
- 1
Topluluk istihbaratı
1 topluluk raporu
KategoriFAKE_RETURNS
[URGENT REPORT] Cryptocurrency Investment Fraud Using Fake Oxford Professor Identity: $407,550 Stolen via Fake Platform 'CFL Group' I sincerely appeal to you and earnestly ask for your help for this reporter. I am a South Korean citizen residing in Seoul who has fallen victim to
VirusTotal Analizi
Bu Siteden Etkilendiniz mi?
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.
Herhangi Bir Alan Adını Kontrol Et
Saklanan engelleme listesi, WHOIS, DNS ve genel tarama kanıtlarını kullanarak tehdit analizi
Şimdi TaraOltalama Olayını Bildir
Şüpheli alan adlarını tehdit veritabanımıza bildirin — topluluğu koruyun
BildirCanlı Tehdit Akışı
Son kimlik avı raporları ve gözlemlenen kullanılabilirlik değişiklikleri
İzleGelişmelerden Haberdar Olun, Güvende Kalın
Canlı tehditleri izleyin veya bunun yanlış bir uyarı olduğunu düşünüyorsanız bu kayda itiraz edin