cyberduck[.]it
“Cyberduck il miglior FTP gratuito - cyberduck.it”
cyberduck.it — Неперевірений. Тип шахрайства: Generic Phishing. Зведення доказів: VirusTotal 7/91 (alphaMountain.ai, BitDefender, Forcepoint ThreatSeeker, G-Data, Gridinsoft); 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 85/100. Реєстратор: TLD Registrar Solutions.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
This domain is flagged as a high-risk phishing site designed to impersonate the legitimate Cyberduck FTP client. Analysis indicates the threat type is brand impersonation, specifically targeting users seeking free FTP software by mimicking the official Cyberduck application. The page title, 'Cyberduck il miglior FTP gratuito - cyberduck.it,' reinforces this deception, likely aiming to harvest login credentials or distribute malicious payloads under the guise of a trusted tool.
Infrastructure analysis reveals the domain was registered on March 17, 2010, through TLD Registrar Solutions Ltd, though its malicious activity appears recent. It resolves to the IP address 35.214.148.249 and currently holds a VirusTotal detection score of 2/95 security vendors. The domain is actively blocked by two security blocklists: OISD and Hagezi. The SSL certificate is issued by Let's Encrypt, a common tactic to lend false legitimacy to phishing sites. Despite its long registration history, the domain's sudden appearance on threat intelligence feeds suggests a compromise or repurposing for malicious intent.
Mitigation steps for this threat type include immediate blocking of the domain and its associated IP (35.214.148.249) at the network perimeter. Users should be advised to verify the authenticity of software downloads by accessing the official vendor site directly, avoiding third-party mirrors or unofficial domains. Security teams should monitor for credential theft attempts or unauthorized access originating from systems that interacted with this domain. If the domain was accessed, reset any credentials entered and scan for malware. Organizations should also review logs for connections to 35.214.148.249 or related indicators to assess potential compromise.
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Аналіз VirusTotal
Аналіз продуктивності сайту
Google PageSpeed Insights — mobile performance audit of cyberduck.it · checked Jul 6, 2026
Аналіз конфігурації сайту
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога