Перейти до звіту про безпеку
⚠️
Цей домен було позначено як шкідливий
Системи безпеки повідомляють про виявлення: 8. Будьте дуже обережні — не вводьте облікові дані чи особисту інформацію.
Безпека домену та аналіз загроз

158-158-1-61[.]cprapid[.]com

“DPD (fr) |”

Загрозливий вердикт Критичний 78/100 оцінка доказів
Доступність Неперевірений Поточна доступність не перевірена
Виявлення VirusTotal: 8/91 Уособлення бренду: Dpd
30.07.2026 Dpd
Огляд звіту

158-158-1-61.cprapid.com — Неперевірений. Уособлення бренду: Dpd; Тип шахрайства: Impersonation. Зведення доказів: VirusTotal 8/91 (alphaMountain.ai, Forcepoint ThreatSeeker, Gridinsoft, Lionic, MalwareURL); URLScan malicious verdict; PhishDestroy score 78/100. Реєстратор: cPanel Rapid.

Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.

Зведення доказів
КРИТИЧНИЙ
Посилання
4C39797A
Оцінка
78/100

Analysis of 158-158-1-61.cprapid.com shows a high‑risk, active generic phishing infrastructure. The domain is hosted on cPanel Rapid, a shared hosting platform that frequently supplies disposable domains for malicious campaigns. DNS resolution points to the IPv4 address 158.158.1.61, confirming a single‑point hosting footprint. The domain appears on one public security blocklist and has been flagged by the PhishDestroy sinkhole, indicating that it has already been identified as malicious by at least one anti‑phishing service.

VirusTotal reports that 2 of 91 scanned security vendors classify the domain as malicious, providing independent confirmation of its threat status. No additional intelligence such as Safe Browsing, Open Threat Exchange, SSL certificate details, or HTTP response codes is currently available, leaving the full surface‑area of the site’s content and transport security unverified. Given the confirmed registrar (cPanel Rapid), the presence on a blocklist, and the VirusTotal detections, defenders should treat any traffic to this domain as hostile.

Recommended mitigations include adding the domain to local deny lists, updating proxy and firewall rules to block outbound connections to 158.158.1.61, and ensuring that email filters reference the blocklist entry. Continuous monitoring of the domain’s resolution and any future VirusTotal scans is advised to capture changes in detection coverage. Organizations should also verify that endpoint protection solutions are configured to flag the domain based on the existing detections, and consider sharing indicator data with threat‑sharing communities to improve collective defenses.

VirusTotal
VirusTotal
8 det.
URLScan
URLScan
ScamAdviser
Scamadviser
80/100
Сертифікат TLS
Прострочений або неперевірений
Зафіксований статус
Неперевірений
PhishDestroy
DestroyList
У списку
Обсяг даних VirusTotal 8 / 91 URLQuery не перевірено PhishStats не перевірено OTX no community references CF Radar scan completed URLScan capture збережений звіт URLScan verdict malicious Блокування DNS не перевірено TLS Прострочений або неперевірений WHOIS not parsed Знімок екрана 3 captures · 2 sources Ланцюжок перенаправлень не досліджено Scamadviser 80/100
Розвіддані з мережевої безпеки
SSL Certificate Invalid
SSL certificate is invalid or expired. Issuer: Let's Encrypt

Процес реагування на загрози Pipeline

Відкриття
Checks
Reports
Доступність
11/13

Статус у публічних блоклистах

Збережений знімок

Заголовок сторінки
DPD (fr) |
Сертифікат TLS
Прострочений або неперевірений · Виданий Let's Encrypt · valid for 88 days

Аналітика доменів

Домен
URLScan Verdict Шкідливий score 100 Phishing brand: Dpd report ↗
Сервер / ASN Apache · AS8075 Microsoft Corporation
Репутація IP abuse score 0/100 0 reports checked 30.07.2026
Registrar (base domain) cPanel Rapid
Контакт для скаргabuse@microsoft.com
IP-адреса 158.158.1.61 ES
ГеолокаціяES Madrid, ES
МережаAS8075 · Microsoft Azure Cloud (spaincentral)
Зворотний пошук IPviewdns.info → rapiddns.io →
Технічні деталіDNS, SAN-адреси SSL, мітки часу
Вперше виявлено30.07.2026
DOM Analysisanalyzed 30.07.2026score 78/100
IoC Extractionscanned 01.08.20260 wallet · 0 Telegram IoCs
Submitted URLhttp://158-158-1-61.cprapid.com/pl/update.php
TLS Fingerprint
TLS Observationvalid from 29.07.2026scanned 30.07.2026
TLS SAN Domainsipv6.paket.info.158-158-1-61.cpanel.sitemail.paket.info.158-158-1-61.cpanel.sitepaket.info.158-158-1-61.cpanel.sitewww.paket.info.158-158-1-61.cpanel.site
ICANN OVERSIGHT Registration: cprapid.com

Акредитація та контекст RAA

Registrar accreditation and DNS abuse obligations

For the registrable domain cprapid.com behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.

Accreditation is a contract, not a safety certification.

RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.

Accountability draft Нічого не надсилається автоматично.
Перехресна перевірка даних про загрози · source references
ScamAdviser Public lookup
A public ScamAdviser lookup is available. Review its current score and warnings at the source; the existence of a lookup page is not itself a malicious verdict.
View on ScamAdviser
Live-fetched via CF worker proxy pool · cached 24h
Поскаржитися на цей домен Надішліть докази та допоможіть захистити інших

Аналіз VirusTotal

8 / 91 постачальників безпеки позначили цей домен
View on VT
Last analyzed Previous stored snapshot: 7 detections
alphaMountain.ai
Forcepoint ThreatSeeker
Gridinsoft
Lionic
MalwareURL
Seclookup
Sophos
Webroot

Архівні докази

Wayback Machine Snapshot
Для перегляду доказів доступний історичний знімок
View Archive
Stored Capture Evidence 1 snapshot

Timestamped response metadata retained by the local collection pipeline. Each value below belongs to the displayed archive time.

Archived HTTP response HTTP 200
Requested URL: http://158-158-1-61.cprapid.com/pl/update.php
DPD (de) |
Реагування
HTTP 200
HTML body
37.4 KB
Compressed
6.9 KB
Links
6 internal · 16 external
Detected technologies
wordpressapache
Selected response headers
Server: Apache
Cache-Control: no-store, no-cache, must-revalidate
Content-Type: text/html; charset=UTF-8
HSTS: not observed DNSSEC: not observed WAF / firewall: observed Cloaking flag: not observed
Favicon fingerprint: a3121842a3e247b2c064c1b5b308f5df597226e3258bb46c9feffbc962d9d040
All stored response-header names (9)
DateServerExpiresCache-ControlPragmaKeep-AliveConnectionTransfer-EncodingContent-Type

Докази та зовнішні звіти

Чи вплинув на вас цей сайт?

If credentials were compromised, report immediately. Do not engage with recovery scammers.

Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.

Європол
Знайдіть офіційний канал звітності для вашої країни ЄС
National police directory
Остерігайтеся шахраїв, які обіцяють повернути втрачені кошти! Злочинці можуть знову зв’язатися з жертвами, видаючи себе за слідчих, адвокатів або агентів із відновлення. Не сплачуйте авансових зборів і не діліться обліковими даними. Дізнайтеся більше про шахрайство у сфері відшкодування збитків →

Зверніться до місцевих органів влади

Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.

Довідник 97 країн
Чернетка за допомогою штучного інтелекту — деталі інциденту обробляються постачальником штучного інтелекту Перегляньте та подайте його самостійно

Перевірити будь-який домен

Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування

Сканувати зараз

Повідомити про фішинг

Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту

Повідомити

Потокова стрічка про загрози

Останні звіти про фішинг і помічені зміни доступності

Відстежувати

Будьте в курсі подій, дбайте про свою безпеку

Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога

Потокова стрічка про загрози Оскаржити це оголошення
HTML · IFRAME

Вбудувати цей звіт

Поділіться цією інформацією про загрози на своєму веб-сайті або в блозі

embed.html
<iframe
  src="https://phishdestroy.io/uk/embed/domain/158-158-1-61.cprapid.com"
  title="PhishDestroy threat report for 158-158-1-61.cprapid.com"
  width="100%" height="320"
  loading="lazy"
  referrerpolicy="no-referrer"
  sandbox="allow-same-origin allow-popups allow-popups-to-escape-sandbox"
  style="border:0;border-radius:12px;max-width:100%"
></iframe>

Дуже щирий лист-подяка

Генератор сатиричних чернеток

Одержувач
Контекст зборів

Це сатирична чернетка. Суми зборів є оцінками; ми не стверджуємо, що вони точно стосуються цього домену.