marchfour[.]icu
Зведення доказів
The domain marchfour.icu is currently flagged as an active phishing host with an elevated risk rating. Defensive feeds indicate that the domain has been blocked by the PhishDestroy network, suggesting that at least one reputable anti-phishing service has identified malicious activity associated with the host. VirusTotal analysis shows that three out of ninety‑one scanning engines have returned a positive detection, confirming that the domain exhibits characteristics typical of phishing infrastructure, though the majority of scanners have not flagged it. Additionally, the domain appears on a single security blocklist, reinforcing the notion that it has been observed in malicious traffic or reported by an external sinkhole.
No public data is available regarding the registrar, registration date, IP address, hosting provider, SSL certificate details, HTTP response codes, Safe Browsing status, or Open Threat Exchange (OTX) entries. Consequently, the precise technical footprint of the site—such as its underlying server location, certificate validity, or page title—remains undocumented in the current intelligence set. The limited detection coverage (3/91) implies that the phishing payload may be using evasion techniques that bypass many conventional scanners, or that the malicious content is transient and only triggered under specific conditions.
Defenders should therefore treat any traffic to marchfour.icu as suspicious and enforce blocking at the network perimeter. Organizations are advised to add the domain to internal URL filtering lists, update endpoint protection signatures to include the three detecting vendors, and monitor for any outbound connections that may indicate credential harvesting attempts. Continuous re‑evaluation is recommended, as additional detection signals may emerge if the campaign expands or if further scanning engines acquire evidence of malicious behavior.
Data Coverage
Розвіддані з мережевої безпеки
Процес реагування на загрози Pipeline
Перевірка за блок-листами
10 зовнішніх джерел під наглядом · знімок від 11.08.2026
Хронологія виявлення
-
Статус домену
Доступний → Недоступний
Аналітика доменів
Технічні подробиціDNS, імена TLS і часові мітки
ЗОНА SHORTDOT · ПУБЛІЧНІ ДОКАЗИ
.icu
ShortDot zone evidence
ShortDot zone evidence
The linked repository preserves daily zone observations across seven ShortDot-operated TLDs, including registration volume and abuse-related indicators. This registry context is supporting background and is not an independent detection for the domain in this report.
Аналіз VirusTotal
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога