unlock-worldlibertyflnanciai[.]xyz
“Sorry, the website has been stopped”
unlock-worldlibertyflnanciai.xyz — Контент недоступний (HTTP 502). Зведення доказів: VirusTotal 15/93 (ADMINUSLabs, ChainPatrol, alphaMountain.ai, BitDefender, CyRadar); 1 external blocklist match (ScamSniffer); PhishDestroy score 95/100.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
The domain unlock-worldlibertyflnanciai.xyz was registered on February 21, 2026 and is presently listed as offline with the page title "Sorry, the website has been stopped." Technical analysis shows the domain resolves to IP address 104.21.82.12, which belongs to Cloudflare, Inc. (ASN13335) and is geolocated in the United States. The site presents a valid SSL certificate identified as WE1, indicating that TLS termination is provided by the Cloudflare network. VirusTotal scans have recorded 15 positive detections out of 93 security vendors, suggesting that multiple independent scanners have identified malicious activity associated with the domain.
The domain is actively blocked by the PhishDestroy and ScamSniffer blocklists and appears on two additional security blocklists, reinforcing the assessment that it has been used for phishing purposes. While the current offline status limits immediate observation of malicious payloads or credential‑harvesting pages, the combination of recent registration, Cloudflare hosting, positive vendor detections, and blocklist listings provides sufficient evidence to classify the domain as a generic phishing infrastructure. Uncertainty remains regarding the specific phishing campaign details, target brands, or victim interaction patterns because no page content beyond the stop message has been captured.
Defenders should continue to enforce blocking of the domain and its associated IP address, monitor for any future resolution changes or re‑hosting on alternative IP ranges, and incorporate the domain hash into internal threat‑intel feeds. Ongoing vigilance on Cloudflare‑hosted assets, especially newly registered domains flagged by multiple vendors, is recommended to pre‑empt potential re‑activation or reuse in subsequent phishing campaigns.
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Аналіз VirusTotal
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога