MALICIOUS — CRITICAL
cblivechat[.]com
11 security engines flagged the domain; 2 public blocklists listed it (MetaMask, SEAL); the latest stored check returned HTTP 502.
- VirusTotal
- 11 detections
- Blocklists
- 2 · MetaMask, SEAL
- Доступність
- Контент недоступний · HTTP 502
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
cblivechat.com — Контент недоступний (HTTP 502). Уособлення бренду: ["argent"]; Тип шахрайства: Generic Phishing. Зведення доказів: VirusTotal 11 detections (engine total unavailable) (ADMINUSLabs, CRDF, CyRadar, ESET, Fortinet); URLQuery 5 alerts; Google Safe Browsing flagged; Spamhaus DBL_PHISH; 2 external blocklist matches (MetaMask, SEAL); CF Radar malicious; PhishDestroy score 90/100. Реєстратор: CNOBIN INFORMATION TEC….
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
Evidence Digest
cblivechat.com is classified critical with an evidence score of 90/100. 11 security engines flagged the domain; 2 public blocklists listed it (MetaMask, SEAL). Registered 10 Mar 2026 via CNOBIN INFORMATION TECHNOLOGY LIMITED, hosted on 91.92.241.15 (Omegatech LTD, NL). The latest stored check on 9 Aug 2026 returned HTTP 502 and includes a capture. 1 outgoing abuse report is recorded, most recently on 10 Mar 2026.
Stored generated summary (templated)mistral · 25.07.2026
Retained for the record. This text repeats stored detection facts and is not presented as authored analysis.
Analysis of the domain cblivechat.com indicates a high-risk phishing operation targeting institutional or private-client financial services. The domain was registered on March 10, 2026, through CNOBIN INFORMATION TECHNOLOGY LIMITED and is currently offline. Infrastructure analysis reveals resolution to the IP address 91.92.241.15, hosted on AS202412 (Omegatech LTD) in the Netherlands. Nameservers ns1.virtualine.org and ns2.virtualine.org are associated with the domain, and no SSL certificate is present.
The page title, 'Institutional: Private Client,' suggests an attempt to mimic legitimate private banking or wealth management platforms, though the exact content and targeted brand remain unconfirmed due to the domain's offline status. Detection data shows the domain has been flagged by 11 of 95 security vendors on VirusTotal, with additional blocking by PhishDestroy, MetaMask, and SEAL. Google Safe Browsing has classified the domain as engaging in social engineering, and it appears on three security blocklists. The use of HTTP/3 is noted, though its significance in this campaign is unclear.
Defenders should treat this domain as malicious, particularly in environments where private-client financial services are accessed. Given the domain's registration details, hosting provider, and detection history, it is recommended to block the domain and associated IP at the network level. Further investigation into related infrastructure, such as nameservers and hosting provider, may reveal additional compromised or malicious assets. No evidence of persistence mechanisms or secondary payload delivery is currently available, but monitoring for re-emergence or similar domains under the same registrar or hosting provider is advised.
Обсяг даних12 recorded checks
Розвіддані з мережевої безпеки
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| OpenDNS | cblivechat.com |
phishing | Phishing Block |
| Cloudflare DNS | cblivechat.com |
malicious | Sinkholed |
| DigiCert UltraDNS | cblivechat.com |
malicious | Sinkholed |
| CIRA Canadian Shield DNS | cblivechat.com |
malicious | Sinkholed |
| DNS4EU | cblivechat.com |
malicious | Sinkholed |
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Збережений знімок
Аналітика доменів
Технічні деталіDNS, SAN-адреси SSL, мітки часу
ICANN OVERSIGHT
Акредитація та контекст RAA
Акредитація та контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Технології · 1 identified
Third major version of HTTP protocol, built on QUIC for faster, more reliable connections.
Аналіз VirusTotal
Аналіз продуктивності сайту
Google PageSpeed Insights — mobile performance audit of cblivechat.com · checked Mar 10, 2026
Докази та зовнішні звітиIndependent lookups and source reports
PD-20260310-41BEF5 Recipient: abuse@ordertld.com Victim safety and official reportingImmediate actions and verified reporting channels
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.