casatua-srl.it
“CasaTua Srl”
casatua-srl.it — 最后已知的活跃状态 (HTTP 301). 品牌冒充:Unknown. 证据摘要: VirusTotal 14/89 (ADMINUSLabs, alphaMountain.ai, BitDefender, CyRadar, Forcepoint ThreatSeeker); PhishDestroy score 100/100. 注册商: Aruba s.p.a.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
证据摘要
PhishDestroy first observed casatua-srl.it on Sep 19, 2026. Stored content metadata identifies Unknown as the apparent target. The captured page title is “CasaTua Srl”. Current evidence score: 100/100 (critical).
One source contains a positive finding: VirusTotal. VirusTotal recorded 14 detections among 89 engines: ADMINUSLabs, alphaMountain.ai, BitDefender, CyRadar, Forcepoint ThreatSeeker, Fortinet, G-Data, Gridinsoft, Lionic, Seclookup, SOCRadar, Sophos, VIPRE, Webroot on Sep 20, 2026 at 13:21 UTC. Non-positive and contextual checks: AlienVault OTX listed 6 community pulse references (not vendor detections) on Sep 20, 2026 at 13:23 UTC. The separate external-blocklist snapshot contained no matches on Sep 20, 2026 at 10:20 UTC. Google Safe Browsing returned no flag on Sep 20, 2026 at 13:22 UTC. URLScan completed without a malicious verdict (score 0) on Sep 20, 2026 at 03:30 UTC.
HTTP 301 was recorded on Sep 20, 2026 at 10:50 UTC. Registration records for the domain list Aruba s.p.a. as the registrar and Oct 16, 2017 as the creation date. At collection time, the hostname resolved to 31.11.36.56 on AS31034 (ARUBA-ASN Aruba S.p.A., IT). The recorded endpoint location is Arezzo, IT. The stored server header is aruba-proxy. DOM analysis on Sep 20, 2026 at 02:20 UTC returned 98/100. The evidence archive retains 3 visual captures from PhishDestroy and URLScan. TLS metadata lists Actalis S.p.A. / Actalis Domain Validated TLS Server RSA CA 2025 as the certificate issuer with validity through Feb 19, 2027; checked Sep 19, 2026 at 22:02 UTC.
Stored content provides classification context, but only one source contains a positive finding. The target field identifies Unknown, but the record does not establish whether the page requested credentials, a seed phrase, or a wallet connection.
Forensic History & Detection Timeline
-
VirusTotal Detections Update Sep 20, 2026 · 06:04 UTCVirusTotal scanner detections updated from 14 to 14. Added scanner alerts: SOCRadar. Resolved alerts: Chong Lua Dao.
-
Threat First Observed Sep 19, 2026 · 23:53 UTCDomain ingestion complete. Initial state is marked as unknown pointing to IP
31.11.36.56.
威胁响应 Pipeline
公共封禁名单状态
Evasion analysis
Cloaking suspected: scanner and victim titles differ
Stored crawler-versus-browser observations for this host, plus a live fingerprint check for Keitaro-style traffic distribution systems.
- Stored cloaking flag
- Not yet scanned
- Last cloaking scan
- Server header seen by scanner
aruba-proxy
Scanner note: redirect: raw=redirect_301; http=301; via=https_proxy; location=https://www.casatua-srl.it/; server=aruba-proxy
技术 · 11 identified
VirusTotal 分析
网站性能分析
Google PageSpeed Insights — mobile performance audit of casatua-srl.it · checked Sep 19, 2026
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。