scotia-connect[.]co[.]com
“Scotia Connect - Official Website - Login”
scotia-connect.co.com — Контент недоступний (HTTP 502). Уособлення бренду: Facebook; Тип шахрайства: Social Media Phishing. Зведення доказів: VirusTotal 14/95 (ADMINUSLabs, alphaMountain.ai, BitDefender, CyRadar, ESET); Spamhaus DBL_PHISH; 3 external blocklist matches (Polkadot, Enkrypt, Codeesura); PhishDestroy score 92/100. Реєстратор: Moniker Online Services.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
Analysis of scotia-connect.co.com, observed as a social media phishing infrastructure targeting Facebook users, indicates a high‑risk profile. The domain resolves to the IPv4 address 193.46.217.224, which is associated with AS400992 ZhouyiSat Communications in the United States. The hosting IP appears on four independent blocklists—PhishDestroy, Polkadot, Enkrypt, and Codeesura—demonstrating that multiple threat‑intelligence feeds have flagged the same host. Gridinsoft assigns the domain a trust score of 0 out of 100, reflecting a lack of credibility.
VirusTotal data shows that 14 of 95 scanned security vendors flagged the domain, further corroborating malicious activity. The domain was originally registered on August 16, 1997 through Moniker Online Services LLC and continues to use the default .co.com name‑server set (ns1.nic.co.com through ns4.nic.co.com). No TLS certificate is presented, meaning traffic is unencrypted and vulnerable to interception. The page title retrieved from the site—"Scotia Connect - Official Website - Login"—does not reference the targeted brand, yet the intelligence explicitly lists Facebook as the impersonated brand, classifying the operation as a social media phishing campaign.
The site is currently offline, but the underlying infrastructure remains reachable via its IP address. Defenders should continue to block the domain and associated IP at perimeter filters, propagate the observed blocklist indicators, and monitor for any re‑activation or reuse of the same hosting resources. Threat‑intel platforms should update their feeds with the observed detection count, blocklist entries, and trust‑score rating to improve future detection.
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Криміналістичні дані
Аналіз VirusTotal
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога