abg276[.]it
“Welcome aboard”
证据摘要
Analysis of the domain abg276.it, as of the report date July 23 2026, shows a recent registration (creation date February 21 2026) and a rapid deployment of phishing‑related infrastructure. The domain presents an SSL certificate identified as WE1, indicating a self‑issued or low‑reputation certificate. DNS resolution points to the IP address 188.114.96.3, which is owned by Cloudflare, Inc. (AS13335) and geolocated to the United States. The hosting choice suggests the operators are leveraging Cloudflare’s CDN and protection services to obscure the true origin of the payload. The site’s only observable attribute is the page title “Welcome aboard,” which provides no direct indication of the targeted brand or credential‑harvesting methodology.
Security telemetry records the domain on a single blocklist and confirms that PhishDestroy has taken it offline. Gridinsoft assigns a trust score of 0 out of 100, reinforcing the assessment of malicious intent. VirusTotal analysis reports that two of ninety‑three scanning engines flagged the domain, offering the only vendor‑level detection evidence available. The combination of a low trust score, blocklist presence, and limited vendor detections aligns with the elevated risk rating assigned to the domain.
Uncertainty remains regarding the exact phishing vector, payload content, and whether any active command‑and‑control communication was established before the takedown, as the site is currently offline and no further HTTP response data is available. Defenders should proactively block the domain and its associated IP address at perimeter firewalls and DNS filtering solutions. Continuous monitoring of DNS queries for the domain and its IP, as well as periodic re‑scanning on VirusTotal or similar platforms, is advised to capture any resurgence or re‑use of the infrastructure. Organizations should also consider updating threat‑intel feeds with the observed indicators to improve detection of related campaigns.
Data Coverage
威胁响应 Pipeline
阻止列表覆盖
监控中的外部数据源 10 个 · 已存快照 2026年8月11日
VirusTotal 分析
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。
检查任意域名
使用存储的阻止列表、WHOIS、DNS 和公共扫描证据进行威胁分析
立即扫描举报网络钓鱼
将可疑域名提交至我们的威胁数据库——保护社区
报告实时威胁动态
最近的网络钓鱼报告和观察到的可用性变化
监控