v2-embednotion[.]com
v2-embednotion.com için kimlik avı ve güvenlik kontrolü
v2-embednotion.com — Bilinen son aktif (HTTP 301). Kanıt özeti: VirusTotal 4/91 (CRDF, Fortinet, Gridinsoft, SOCRadar); Spamhaus DBL_PHISH; 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 83/100. Kayıt kuruluşu: Cloudflare.
Özgün adli kaydı korumak için aşağıdaki ayrıntılı PhishDestroy AI analizi İngilizce bırakılmıştır.
Evidence Analysis
The domain v2-embednotion.com was registered on May 01, 2026 through Cloudflare, Inc. and is currently marked as active with a high risk rating. It presents a Let's Encrypt certificate (E7) and is delegated to the Cloudflare name servers katja.ns.cloudflare.com and razvan.ns.cloudflare.com. The HTTP response returns a 401 status, indicating that the web server is protecting content behind authentication or that the page is intentionally restricted.
Infrastructure analysis shows the domain resolves to IP address 172.67.154.248, which belongs to Cloudflare’s network located in Canada. The address appears on three external security blocklists and has been recorded in a single AlienVault OTX pulse. Gridinsoft assigns a trust score of 0 out of 100, while popular blocklists such as PhishDestroy, MetaMask, and SEAL have already listed the domain as malicious. VirusTotal currently reports 0 detections out of 95 analyses, reflecting the lack of a public payload at the time of scanning.
Despite the collected indicators, the precise phishing payload and target audience remain unclear. The 401 response prevents automated content retrieval, and no malware signatures have been observed on the host. Absence of detections on VirusTotal does not imply benign intent, but rather that the site’s malicious content is not yet visible to scanners. Consequently, attribution to a specific phishing kit or campaign template cannot be confirmed at this stage.
Continue analysis 1 more sections
Defenders should immediately block v2-embednotion.com at network perimeters and add the associated IP address to deny lists. Continuous monitoring of DNS resolutions and blocklist updates is advised, as the infrastructure may shift to new IP ranges. Organizations should alert end‑users to the potential for credential harvesting attempts hosted on this domain and enforce multi‑factor authentication where possible.
Veri kapsamı12 recorded checks
Tehdit Müdahale Pipeline
Genel Engelleme Listesi Durumu
Etki Alanı Analizi
Teknik ayrıntılarDNS, SSL SAN’ları, zaman damgaları
ICANN OVERSIGHT
Akreditasyon ve RAA bağlamı
Akreditasyon ve RAA bağlamı
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
VirusTotal Analizi
Kanıtlar ve Dış RaporlarIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.