whale-ai[.]cfd
“Whale AI”
Kanıt özeti
The domain whale-ai.cfd was registered on February 21, 2026 and is currently taken offline. Infrastructure analysis shows it resolves to the IP address 172.67.154.91, which belongs to AS13335 Cloudflare, Inc. and is geolocated in the United States. The SSL certificate presented for the site is identified as WE1, indicating a standard TLS termination provided by the hosting provider. The page title returned by the server is "Whale AI," and the domain is classified under the scam type "Brand Impersonation" with a specific target of the Telegram brand.
Threat intelligence sources list the domain on two security blocklists, PhishDestroy and ScamSniffer, confirming its malicious reputation. VirusTotal scans have resulted in three of ninety‑three security vendors flagging the domain, reinforcing the presence of malicious indicators. Additionally, Gridinsoft assigns a trust score of 0 out of 100, reflecting an extremely low confidence in the domain’s legitimacy. While the site is currently offline, the combination of blocklist listings, vendor detections, a zero trust score, and the explicit brand impersonation claim provide substantive evidence of malicious intent.
Uncertainty remains regarding the exact content that was served before takedown, as no visual or functional analysis is available beyond the page title. Defenders should immediately block any outbound or inbound traffic to 172.67.154.91 and add whale-ai.cfd to URL filtering policies. Security operations teams ought to monitor for new domains that resolve to the same Cloudflare IP range and update detection signatures to capture the "Whale AI" page title pattern. Continuous review of threat intel feeds for additional detections related to this domain is recommended to maintain situational awareness.
Data Coverage
Tehdit Müdahale Pipeline
Engelleme listesi kapsamı
10 izlenen harici kaynak · kayıtlı anlık görüntü 13.08.2026
Kaydedilen görüntü
Etki Alanı Analizi
Teknik ayrıntılarDNS, TLS adları ve zaman damgaları
SHORTDOT BÖLGESİ · KAMUYA AÇIK KANIT
.cfd
ShortDot zone evidence
ShortDot zone evidence
The linked repository preserves daily zone observations across seven ShortDot-operated TLDs, including registration volume and abuse-related indicators. This registry context is supporting background and is not an independent detection for the domain in this report.
Adli İstihbarat
VirusTotal Analizi
Bu Siteden Etkilendiniz mi?
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.
Herhangi Bir Alan Adını Kontrol Et
Saklanan engelleme listesi, WHOIS, DNS ve genel tarama kanıtlarını kullanarak tehdit analizi
Şimdi TaraOltalama Olayını Bildir
Şüpheli alan adlarını tehdit veritabanımıza bildirin — topluluğu koruyun
BildirCanlı Tehdit Akışı
Son kimlik avı raporları ve gözlemlenen kullanılabilirlik değişiklikleri
İzleGelişmelerden Haberdar Olun, Güvende Kalın
Canlı tehditleri izleyin veya bunun yanlış bir uyarı olduğunu düşünüyorsanız bu kayda itiraz edin