state[.]ghbpay[.]cc
Зведення доказів
PhishDestroy identifies state.ghbpay.cc as an active credential theft phishing domain targeting unsuspecting users. This domain mimics legitimate payment or financial service portals to harvest login credentials, payment details, or other sensitive information. No direct association with a specific brand or crypto drainer kit has been confirmed at this time, but the domain structure and naming convention suggest an intent to deceive users into believing it is a trusted payment gateway. The lack of brand impersonation markers indicates a broader, opportunistic credential harvesting approach rather than a targeted campaign. Technical analysis reveals that state.ghbpay.cc currently holds a VirusTotal detection score of 5/95, indicating no antivirus engines have flagged it as malicious at the time of investigation. The domain resolves to the IP address 170.106.51.191, which may host additional malicious infrastructure. Registrar details and domain creation date remain undisclosed, limiting further attribution. Google Safe Browsing (GSB) status is unconfirmed, and no blocklist entries have been reported. The absence of detections does not equate to safety, as phishing domains often evade detection during their initial deployment phase. As of the latest assessment, state.ghbpay.cc has been taken offline, reducing immediate exposure risk to users. However, the domain may resurface under a different IP or with altered infrastructure. Response actions include monitoring for re-emergence and submitting the domain to threat intelligence platforms for broader awareness. Users who may have interacted with this domain are advised to change passwords, enable multi-factor authentication, and review financial statements for unauthorized activity. Organizations should update email and web filtering rules to block access to this domain and its associated IP. Vigilance remains critical, as credential theft domains often rotate quickly to evade detection.
Data Coverage
Процес реагування на загрози Pipeline
Перевірка за блок-листами
10 зовнішніх джерел під наглядом · знімок від 11.08.2026
Аналітика доменів
Технічні подробиціDNS, імена TLS і часові мітки
Аналіз VirusTotal
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога