ca[.]citicapitalunion[.]com
“Citicapitalunion”
ca.citicapitalunion.com — 内容不可用. 品牌冒充:Google; 诈骗类型:Tech Support Scam. 证据摘要: VirusTotal 1/93 (Gridinsoft); PhishDestroy score 56/100.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
Analysis of ca.citicapitalunion.com shows that the domain was registered on February 21, 2026 and is currently taken offline. DNS resolution points to the IP address 86.107.77.178, which belongs to Autonomous System AS216395 operated by HostBet Cloud Technologies Private Limited and is geolocated in Germany. The site presented a page title of "Citicapitalunion" and was classified as impersonating Google, with the underlying scam type identified as a tech support scam. Reputation scoring from Gridinsoft assigned a trust score of 0 out of 100, indicating an extremely low confidence in legitimacy.
The domain appears on a single security blocklist and has been blocked by the PhishDestroy filtering service. SSL certificate metadata is recorded as "R10," though no further certificate details are available. VirusTotal analysis recorded a single positive detection out of 93 scanned security vendors, confirming that at least one vendor flagged the domain as malicious. The available evidence confirms that the domain was used to host a tech support scam leveraging the Google brand, but the exact content and payload of the site remain unverified because the site is offline.
Uncertainty remains regarding the specific phishing kits or malware payloads that may have been delivered. Defenders should continue to block the associated IP address, enforce domain-based filtering for ca.citicapitalunion.com, and monitor for any re‑activation attempts. Adding the domain to internal blocklists and sharing the indicator set with threat‑sharing communities will reduce exposure to the identified tech‑support impersonation campaign.
威胁响应 Pipeline
公共封禁名单状态
取证情报
VirusTotal 分析
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。