cr738267-wordpress-98tnq[.]tw1[.]ru
“Домен припаркован в Timeweb”
cr738267-wordpress-98tnq.tw1.ru — Неперевірений. Уособлення бренду: Wordpress; Тип шахрайства: Brand Impersonation. Зведення доказів: VirusTotal 12/91 (ADMINUSLabs, alphaMountain.ai, BitDefender, CyRadar, ESET); PhishDestroy score 91/100. Реєстратор: TW-Cloud (ASN: 9123).
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
This domain, cr738267-wordpress-98tnq.tw1.ru, was designed to mimic the official WordPress platform, a tactic commonly used to deceive users into entering credentials or downloading malicious content. Brand impersonation of this nature typically targets individuals or organizations managing websites, tricking them into believing they are interacting with legitimate WordPress services. The site could have been used to distribute malware, harvest login details, or redirect victims to other fraudulent pages. Analysis indicates the domain was flagged by 11 out of 95 security vendors on VirusTotal, a clear indicator of its malicious intent. It was registered through TW-Cloud (ASN: 9123) and resolved to an IPv6 address (2a03:6f00:1::5c35:6069) hosted in Russia under JSC TIMEWEB. The domain appeared on two security blocklists, including PhishDestroy and PhishingDB, and was taken offline following detection. The SSL certificate, issued by GlobalSign, does not mitigate the threat, as fraudulent sites often use valid certificates to appear legitimate. If you visited this domain or interacted with its content, immediate action is required. First, disconnect the affected device from the network to prevent potential lateral movement of malware. Run a full system scan using updated security tools to detect and remove any malicious payloads. If credentials were entered, change passwords for all associated accounts, especially those linked to WordPress or other web management platforms. Monitor accounts for unauthorized activity and enable multi-factor authentication where possible. Report the incident to your organization’s security team or a trusted cybersecurity professional for further analysis.
Сигнали безпеки
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Аналіз VirusTotal
Архівні докази
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога