zfjqcl[.]top
zfjqcl.top — Контент недоступний (HTTP 502). Зведення доказів: VirusTotal 2/93 (alphaMountain.ai); 2 external blocklist matches (ScamSniffer, Enkrypt); PhishDestroy score 66/100.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
Analysis indicates that the domain zfjqcl.top was registered on February 21 2026 and subsequently observed by multiple threat intelligence sources. The domain resolves to the IPv4 address 208.91.196.46, which belongs to the AS40034 network operated by Confluence Networks Inc. and is geolocated in the United States. The hosting IP appears on three independent blocklists—PhishDestroy, ScamSniffer, and Enkrypt—confirming that it is associated with malicious activity. The site employed an SSL certificate identified as R10, but no additional certificate details are publicly disclosed.
VirusTotal scans show that two out of ninety‑three security vendors flagged the domain as malicious, reinforcing the blocklist observations. The domain’s current operational status is reported as offline, suggesting that the phishing infrastructure has been taken down or is no longer serving content. No publicly available page title, brand target, or detailed payload information has been released, leaving the exact phishing vector unverified.
Defenders should continue to block the domain and its associated IP address at network perimeter devices, ensure that the three blocklists are incorporated into existing URL filtering solutions, and monitor for any re‑appearance of the IP or similar registrant patterns. Ongoing reconnaissance of the registrar and DNS records is advised to detect potential repurposing of the domain or related infrastructure. The limited detection footprint—three blocklists and two vendor flags—indicates a low‑volume campaign, but the elevated risk rating warrants proactive mitigation.
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Криміналістичні дані
Аналіз VirusTotal
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога