magnesiummoon[.]entry-cryptolist[.]app
“CRYPTOLIST”
magnesiummoon.entry-cryptolist.app — Контент недоступний. Зведення доказів: VirusTotal 14/91 (ADMINUSLabs, BitDefender, Chong Lua Dao, CyRadar, ESET); PhishDestroy score 92/100.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
magnesiummoon.entry-cryptolist.app is currently flagged as an active generic phishing infrastructure with an elevated risk rating. The domain resolves to the IPv4 address 188.114.96.3, which is hosted on a service that is listed by at least one public security blocklist. No authoritative nameserver records could be retrieved, suggesting that the domain may be using dynamic or obscured DNS services to hinder attribution. Detection engines on VirusTotal have marked the domain as malicious in 14 of 91 submitted scans, indicating that a subset of vendors have identified malicious behavior associated with the host.
The blocklist entry and the VirusTotal detections were both captured by the PhishDestroy feed, which has already listed the domain as blocked. No additional intelligence such as SSL certificate details, HTTP response codes, or page title content is presently available, leaving the exact phishing payload and target brand undefined. The lack of visible infrastructure footprints, combined with the modest detection count, points to a possibly short‑lived campaign that relies on rapid domain turnover. Defenders should prioritize immediate containment by adding the domain and its resolved IP address to network deny lists and by ensuring that email filtering solutions reference the PhishDestroy feed.
Continuous monitoring of the 188.114.96.3 address for new hostnames or changes in DNS configuration is advised, as the operator may rotate to new domains while retaining the same hosting infrastructure. Organizations that employ threat‑intelligence platforms should ingest the blocklist indicator and correlate it with any internal logs that reference the same IP or domain to identify potential compromised user interactions. Because the domain lacks public DNS delegation, passive DNS collection may be useful to capture future name resolution events.
Розвіддані з мережевої безпеки
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Збережений знімок
Аналітика доменів
Технічні деталіDNS, SAN-адреси SSL, мітки часу
Аналіз VirusTotal
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога