cblogin[.]shop
“Index of /”
cblogin.shop — Контент недоступний. Тип шахрайства: Credential Phishing. Зведення доказів: VirusTotal 5/95 (alphaMountain.ai, CyRadar, Fortinet, SOCRadar, Webroot); PhishDestroy score 78/100. Реєстратор: NameCheap.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
This domain is flagged as a high-risk credential phishing site targeting user authentication data. Analysis indicates a deliberate infrastructure setup designed to harvest login credentials through deceptive landing pages, with the page title 'Index of /' suggesting an exposed directory structure often exploited for malicious purposes. The domain poses an immediate threat to users who may be lured into entering sensitive information under false pretenses. Infrastructure analysis reveals multiple high-confidence indicators of compromise. The domain cblogin.shop is registered through NameCheap, Inc., and resolves to the IP address 91.222.173.30, hosted in the Netherlands under AS43641 (SOLLUTIUM EU Sp z.o.o.). It was created on September 3, 2025, indicating recent deployment for malicious activity. Security vendors on VirusTotal flag the domain as malicious, with 5 out of 95 detections confirming its phishing nature. The domain appears on one security blocklist and lacks an SSL certificate, further reducing its legitimacy. The absence of encryption and the use of a newly registered domain align with common phishing tactics to evade detection and establish short-lived attack vectors. Mitigation steps should focus on immediate containment and user awareness. Network administrators are advised to block the domain cblogin.shop and its resolving IP 91.222.173.30 at the firewall or DNS level to prevent access. End-users should be educated on recognizing credential phishing attempts, particularly those mimicking login portals or exposing directory listings. Organizations should enforce multi-factor authentication (MFA) to reduce the impact of stolen credentials. Additionally, monitoring for unusual authentication attempts or traffic to the identified IP address can help detect and respond to potential breaches. Given the domain's recent registration and active status, continuous vigilance is recommended to mitigate evolving threats from this infrastructure.
Сигнали безпеки
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Збережений знімок
Аналітика доменів
Технічні деталіDNS, SAN-адреси SSL, мітки часу
ICANN OVERSIGHT
Акредитація та контекст RAA
Акредитація та контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Аналіз VirusTotal
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога