att[.]lviud[.]icu
“Welcome to nginx!”
att.lviud.icu — Контент недоступний. Зведення доказів: VirusTotal 21/93 (ADMINUSLabs, Criminal IP, alphaMountain.ai, BitDefender, Cluster25); Spamhaus DBL_PHISH; PhishDestroy score 95/100.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
This domain, att.lviud.icu, is flagged as a brand impersonation threat targeting users of the social media platform X.com. Analysis indicates the infrastructure was designed to deceive victims into believing they are accessing a legitimate login portal, likely for credential harvesting. The page title 'Welcome to nginx!' suggests misconfigured or placeholder content, though this does not diminish the domain's malicious intent. No evidence of a crypto drainer kit was observed in the available data, but the focus on brand impersonation aligns with common credential theft tactics. Infrastructure analysis reveals the domain was registered on February 21, 2026, an unusually future-dated creation likely indicative of fraudulent activity or data manipulation. It resolves to the IPv6 address 2606:4700:3036::6815:43eb, hosted on Cloudflare's network (AS13335), a common obfuscation tactic to evade detection. The domain is flagged by 21 out of 95 security vendors on VirusTotal, and it appears on one security blocklist. The SSL certificate is classified as WE1, a low-assurance category often associated with automated or short-lived certificates. No Google Safe Browsing (GSB) detections were noted at the time of analysis, though this does not preclude prior or subsequent flagging. The domain is currently offline, reducing immediate risk to end users. However, the infrastructure remains registered and could be reactivated or repurposed for future campaigns. The future-dated creation timestamp suggests potential registrar abuse or domain generation algorithm (DGA) activity, warranting continued monitoring. Users who may have interacted with this domain are advised to reset credentials for X.com and any other accounts where identical passwords were reused. Organizations should update blocklists to include this domain and its associated indicators, while security teams should investigate for related infrastructure using the same IPv6 prefix or SSL certificate patterns.
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Збережений знімок
Аналітика доменів
Технічні деталіDNS, SAN-адреси SSL, мітки часу
ЗОНА SHORTDOT · ПУБЛІЧНІ ДОКАЗИ
.icu
ShortDot zone evidence
ShortDot zone evidence
The linked repository preserves daily zone observations across seven ShortDot-operated TLDs, including registration volume and abuse-related indicators. This registry context is supporting background and is not an independent detection for the domain in this report.
Криміналістичні дані
Аналіз VirusTotal
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога