MALICIOUS — CRITICAL
ibkrgroup[.]cc
The domain ibkrgroup.cc was registered through Dominet (HK) Limited on 21 February 2026 and is hosted on the IP address 45.207.194.25, which belongs to AS401696 cognetcloud INC in Hong Kong.
- VirusTotal
- 11/93
- Blocklists
- 2 · MetaMask, SEAL
- sẵn có
- Nội dung không có sẵn · HTTP 502
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
ibkrgroup.cc — Nội dung không có sẵn (HTTP 502). Tóm tắt bằng chứng: VirusTotal 11/93 (alphaMountain.ai, BitDefender, CRDF, CyRadar, Forcepoint ThreatSeeker); URLQuery 2 alerts; 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 91/100. Nhà đăng ký: Dominet (HK).
Phân tích chi tiết của PhishDestroy AI bên dưới được giữ bằng tiếng Anh để bảo toàn hồ sơ pháp chứng gốc.
Evidence Analysis
The domain ibkrgroup.cc was registered through Dominet (HK) Limited on 21 February 2026 and is hosted on the IP address 45.207.194.25, which belongs to AS401696 cognetcloud INC in Hong Kong. The authoritative name servers are ns1.domainnamedns.com, ns2.domainnamedns.com, ns3.domainnamedns.com and ns4.domainname, indicating use of a generic DNS provider. Service fingerprinting shows the web server runs Nginx with HTTP/3 enabled and HSTS enforced, but no TLS certificate is presented, implying the site was reachable only over plain HTTP before being taken offline. The page title was not captured, and the site currently returns no content, consistent with the reported offline status.
Three public phishing blocklists have listed ibkrgroup.cc, and it is actively blocked by PhishDestroy, MetaMask, and SEAL. VirusTotal scans recorded 11 detections out of 93 security‑engine submissions, reinforcing the malicious classification. No additional intelligence such as a specific brand impersonated or a phishing kit identifier is available, leaving the exact lure unknown. Defenders should continue to block the domain at perimeter devices and update DNS‑based deny lists.
Monitoring of the hosting IP 45.207.194.25 for new activity is advisable, as the infrastructure could be repurposed for other campaigns. Because the site lacks an SSL certificate, any future activation would be visible on network traffic without encryption, enabling detection via proxy or IDS signatures. Analysts should also watch for new registrations using the same registrar and name‑server pattern, as these may indicate a recurring threat actor infrastructure.
Phạm vi dữ liệu12 recorded checks
Tình báo an ninh mạng
Pipeline ứng phó với các mối đe dọa
Trạng thái trong danh sách chặn công khai
Công nghệ · 3 identified
High-performance HTTP server and reverse proxy, known for stability and low resource usage.
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
Third major version of HTTP protocol, built on QUIC for faster, more reliable connections.
Phân tích của VirusTotal
Bằng chứng lưu trữ
Bằng chứng và các báo cáo bên ngoàiIndependent lookups and source reports
PD-20260219-739ADB Recipient: domainabuse@service.aliyun.com Victim safety and official reportingImmediate actions and verified reporting channels
Nếu bạn đã nhập thông tin xác thực tài khoản, thông tin cá nhân hoặc thông tin thanh toán hoặc đã tải xuống tệp từ miền này, hãy hành động ngay lập tức. Dưới đây là các nguồn lực giúp bạn báo cáo vụ việc và bảo vệ chính mình.
Hãy báo cáo với chính quyền địa phương
Chọn quốc gia của bạn để nhận liên hệ tội phạm mạng chính thức hoặc soạn thảo đơn khiếu nại →.