document-sign-online--xfinityweb[.]replit[.]app
“Login Screen”
Збережене спостереження
Зафіксована відмінність заголовків
Зведення доказів
The domain document-sign-online--xfinityweb.replit.app is actively used in a credential‑harvesting campaign and remains live as of the report date, August 06, 2026. Registration information shows the domain was created through Replit Inc., a platform that provides hosting and development environments. Infrastructure analysis reveals that the domain resolves to the IP address 34.117.33.233, which is consistent with Replit’s public hosting range. The domain’s authoritative name server data is unavailable (NS_NOT_FOUND), indicating either a misconfiguration or deliberate concealment of DNS details.
Threat intelligence sources have applied mitigations: the domain is listed on one security blocklist and has been blocked by the PhishDestroy service, confirming that at least one protective feed has recognized the malicious activity. VirusTotal scans show that 15 out of 91 security vendors flagged the domain, providing independent corroboration of its malicious nature. No additional data such as Safe Browsing status, SSL certificate details, HTTP response codes, or page title have been disclosed, leaving the exact content and delivery mechanisms unverified.
Defenders should prioritize immediate blocking of the domain at network perimeter and DNS filtering layers, incorporate the associated IP address into host‑based deny lists, and monitor outbound connections for traffic to 34.117.33.233. Continuous observation of the domain’s status on blocklists and future VirusTotal scans is recommended to gauge any changes in detection coverage. Organizations using URL filtering should ensure that the domain is added to their threat feed updates, and incident response teams should be alerted to potential credential‑theft attempts that reference this domain, especially where users are directed to upload or sign documents online.
Data Coverage
Розвіддані з мережевої безпеки
Процес реагування на загрози Pipeline
Перевірка за блок-листами
10 зовнішніх джерел під наглядом · знімок від 12.08.2026
Хронологія виявлення
-
Перший запис
Перше збережене значення: Доступний
-
Статус домену
Доступний → Недоступний
Збережений знімок
Аналітика доменів
Технічні подробиціDNS, імена TLS і часові мітки
ICANN OVERSIGHT
Registration: replit.app
Акредитація та контекст RAA
Акредитація та контекст RAA
Registrar accreditation and DNS abuse obligations
For the registrable domain replit.app behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Технології
Виявлено 7 технологій із високою впевненістю
Аналіз VirusTotal
Архівні докази
Аналіз продуктивності сайту
Google PageSpeed Insights — mobile performance audit of document-sign-online--xfinityweb.replit.app · checked Aug 6, 2026
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога