cj106932-wordpress-urg2s[.]tw1[.]ru
“WordPress”
cj106932-wordpress-urg2s.tw1.ru — 未验证. 品牌冒充:Wordpress; 诈骗类型:Brand Impersonation. 证据摘要: VirusTotal 12/91 (alphaMountain.ai, BitDefender, Chong Lua Dao, CyRadar, ESET); Google Safe Browsing flagged; PhishDestroy score 98/100. 注册商: TW-Cloud (ASN: 9123).
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
This domain, cj106932-wordpress-urg2s.tw1.ru, is currently active and hosts a brand‑impersonation campaign targeting WordPress. Infrastructure analysis reveals that the domain resolves to IP 92.53.96.105, which belongs to ASN 9123 (JSC TIMEWEB) and is geolocated in Russia. The domain was registered through the TW‑Cloud registrar, and its authoritative name servers are ns1.timeweb.ru, ns2.timeweb.ru, ns3.timeweb.org, and ns4.timeweb.org. TLS termination is provided by a GlobalSign nv‑sa certificate chained to the GlobalSign GCC R3 DV TLS CA 2020, indicating a valid‑looking HTTPS service. An HTTP request to the site returns a 302 redirect, and the page title reported by scanners is “WordPress”, matching the declared brand target.
Reputation services have listed the domain on two blocklists, specifically PhishDestroy and PhishingDB, and Google Safe Browsing flags it for SOCIAL_ENGINEERING. VirusTotal scans show that 13 out of 95 security vendors have flagged the domain as malicious. The Gridinsoft trust score is 0 / 100, reinforcing the classification as high‑risk. The overall risk level is marked as high, and the campaign status remains active.
Analysis indicates that the observable indicators—IP address, ASN, SSL certificate, redirect behavior, and multiple vendor detections—strongly support the presence of a WordPress brand‑impersonation operation. No public content analysis is available, so the exact phishing page structure and credential‑harvesting mechanisms remain unknown. Defenders should block the domain and its resolving IP at network perimeter devices, update URL filtering lists with the identified blocklist entries, and monitor for any traffic to the associated nameservers. Continuous re‑evaluation is advised, as additional detections may emerge from further sandbox or endpoint analysis.
威胁响应 Pipeline
公共封禁名单状态
VirusTotal 分析
存档证据
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。