sso-itrustcapital--logi[.]webflow[.]io
“iTrustCapital Log In”
Kanıt özeti
Analysis of sso-itrustcapital--logi.webflow.io shows a domain that has been deliberately taken offline, yet its historical footprint retains several indicators of abuse. The domain was registered on May 08 2013 through MarkMonitor, Inc., a registrar commonly used for high‑value brands, and is served by Cloudflare nameservers (journey.ns.cloudflare.com and lamar.ns.cloudflare.com). DNS resolution points to IP 104.18.36.248, an address owned by Cloudflare (AS13335) located in the United States. The TLS certificate presented is issued by Google Trust Services under the WE1 label, confirming that the site once used a valid HTTPS configuration.
The page title that was observed, "iTrustCapital Log In," aligns with a credential‑phishing pattern targeting the iTrustCapital brand. VirusTotal reports that 13 of 95 scanning engines flagged the domain, and the site is listed on at least one public blocklist. Additional confirmation comes from PhishDestroy, which has actively blocked the domain. Technical fingerprints show Cloudflare’s HTTP/3 support, while the HTTP response returned a 404 status, indicating that the specific landing page is no longer accessible.
Defenders should treat the domain as a confirmed credential‑phishing threat despite its offline state. The combination of a brand‑specific page title, multiple vendor detections, and blocklist inclusion provides concrete evidence of malicious intent. Security controls such as URL filtering, DNS sink‑holing, and email gateway rules should continue to deny any traffic to this host. Monitoring for future re‑hosting on other Cloudflare IPs or similar subdomains is advisable, as threat actors often recycle infrastructure. Until the domain is officially removed from blocklists, it should remain on deny lists to protect users from potential credential harvesting attempts.
Data Coverage
Tehdit Müdahale Pipeline
Engelleme listesi kapsamı
10 izlenen harici kaynak · kayıtlı anlık görüntü 13.08.2026
Tespit zaman çizelgesi
-
Cloudflare Radar
Cloudflare Radar taraması kaydedildi · Taramayı aç
-
Alan adı durumu
Erişilebilir → Erişilemiyor
-
Cloudflare Radar
Cloudflare Radar taraması kaydedildi · Taramayı aç
-
Cloudflare Radar
Cloudflare Radar taraması kaydedildi · Taramayı aç
Teknolojiler
2 yüksek güvenli teknoloji belirlendi
VirusTotal Analizi
Arşivlenmiş Kanıtlar
Bu Siteden Etkilendiniz mi?
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.
Herhangi Bir Alan Adını Kontrol Et
Saklanan engelleme listesi, WHOIS, DNS ve genel tarama kanıtlarını kullanarak tehdit analizi
Şimdi TaraOltalama Olayını Bildir
Şüpheli alan adlarını tehdit veritabanımıza bildirin — topluluğu koruyun
BildirCanlı Tehdit Akışı
Son kimlik avı raporları ve gözlemlenen kullanılabilirlik değişiklikleri
İzleGelişmelerden Haberdar Olun, Güvende Kalın
Canlı tehditleri izleyin veya bunun yanlış bir uyarı olduğunu düşünüyorsanız bu kayda itiraz edin