alabama[.]mobile-kwa[.]vip
“mobile-kwa.vip | 521: Web server is down”
alabama.mobile-kwa.vip — Неперевірений. Тип шахрайства: Credential Phishing. Зведення доказів: VirusTotal 9/91 (BitDefender, Forcepoint ThreatSeeker, Fortinet, G-Data, Gridinsoft); PhishDestroy score 88/100. Реєстратор: Gname.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
This domain is flagged for credential harvesting phishing, a threat type designed to deceive users into submitting sensitive authentication details via fraudulent login interfaces. The risk level is classified as elevated due to confirmed malicious infrastructure and active security vendor detections, though the domain is currently offline. Analysis indicates the domain alabama.mobile-kwa.vip was registered through Gname.com Pte. Ltd. on June 12, 2026, an anomalous future date suggesting registry manipulation or data obfuscation. It resolves to IP address 172.67.194.157, a hosting provider often associated with malicious campaigns. VirusTotal reports 10 out of 95 security vendors flagging the domain as malicious, while a single security blocklist has incorporated it into their filtering rules. The SSL certificate is issued by Google Trust Services, which, while legitimate, is frequently leveraged by threat actors to lend false credibility to phishing pages. Mitigation steps for this threat type include immediate blocking of the domain and its associated IP (172.67.194.157) at the network perimeter. Security teams should deploy indicators of compromise (IOCs) into endpoint detection and response (EDR) systems, including the domain, IP, and SSL certificate thumbprint for retrospective hunting. User awareness training should emphasize recognizing phishing tactics, particularly those mimicking mobile authentication portals. Additionally, organizations should monitor for anomalous login attempts or credential reuse stemming from this campaign, as harvested credentials may be exploited in follow-on attacks.
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Збережений знімок
Аналітика доменів
Технічні деталіDNS, SAN-адреси SSL, мітки часу
ICANN OVERSIGHT
Registration: mobile-kwa.vip
Акредитація та контекст RAA
Акредитація та контекст RAA
Registrar accreditation and DNS abuse obligations
For the registrable domain mobile-kwa.vip behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Технології · 2 identified
Cloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com 100% впевненостіHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100% впевненостіАналіз VirusTotal
Аналіз продуктивності сайту
Google PageSpeed Insights — mobile performance audit of alabama.mobile-kwa.vip · checked Jun 25, 2026
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога