orldassets[.]entry-cryptolist[.]app
“CRYPTOLIST”
Зведення доказів
Analysis of the domain orldassets.entry-cryptolist.app, observed on 2026-07-29, classifies it as an active generic phishing infrastructure with an elevated risk rating. The domain resolves to the IPv4 address 188.114.97.3, which is currently listed on a single external blocklist and is explicitly blocked by the PhishDestroy mitigation service. DNS interrogation did not return any authoritative nameserver records, as indicated by the placeholder NS_NOT_FOUND, suggesting either deliberately concealed name server configuration or a failure in the query process. VirusTotal scanning shows that 15 out of 91 antivirus and URL-reputation engines have generated a malicious verdict for the domain, reinforcing the suspicion of phishing behavior.
The presence of multiple vendor detections, combined with the blocklist entry and active blocking by PhishDestroy, provides sufficient technical evidence for security teams to treat the domain as hostile. Uncertainties remain regarding the underlying web content, TLS certificate details, HTTP response codes, and the specific phishing lure employed, because these attributes have not been publicly disclosed or captured in the available intelligence. Consequently, the exact victim-targeting vector and any associated credential-harvesting pages cannot be described at this time.
Defenders should prioritize adding the domain to internal blocklists, enforce DNS sink-holing for the resolved IP address, and monitor network traffic for connections to 188.114.97.3. Additional sandbox or manual analysis of the live site, if safely isolated, would be required to obtain payload samples, page titles, and any embedded malicious scripts. Continuous re-evaluation is advised, as further detection updates from additional security vendors may alter the threat posture.
Data Coverage
Розвіддані з мережевої безпеки
Процес реагування на загрози Pipeline
Перевірка за блок-листами
10 зовнішніх джерел під наглядом · знімок від 13.08.2026
Хронологія виявлення
-
Cloudflare Radar
Сканування Cloudflare Radar збережено · Відкрити сканування
-
VirusTotal
3 → 15
-
Статус домену
Доступний → Недоступний
Аналітика доменів
Технічні подробиціDNS, імена TLS і часові мітки
Аналіз VirusTotal
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога