collaber[.]cfd
collaber.cfd 网络钓鱼与安全检查
“Sign in - Google Accounts”
collaber.cfd — 内容不可用 (HTTP 502). 品牌冒充:Google; 诈骗类型:Credential Phishing. 证据摘要: VirusTotal 19/93 (ADMINUSLabs, alphaMountain.ai, BitDefender, Cluster25, CRDF); URLQuery 5 alerts; Spamhaus DBL_PHISH; PhishDestroy score 95/100.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
PhishDestroy first observed collaber.cfd on Feb 26, 2026. Stored content metadata identifies Google as the apparent target. The captured page title is “Sign in - Google Accounts”. Stored page analysis classifies the content as credential phishing. Current evidence score: 95/100 (critical).
Positive findings are stored from 3 sources: VirusTotal, Spamhaus DBL, and URLQuery. VirusTotal recorded 19 detections among 93 engines: ADMINUSLabs, alphaMountain.ai, BitDefender, Cluster25, CRDF, CyRadar, Forcepoint ThreatSeeker, Fortinet, G-Data, Google Safebrowsing, Gridinsoft, Kaspersky, Lionic, Seclookup, SOCRadar, Sophos, Trustwave, VIPRE, Webroot on Feb 25, 2026 at 01:12 UTC. Spamhaus DBL: DBL_PHISH on Jul 14, 2026 at 02:38 UTC. URLQuery recorded 5 threat-system alerts on Jan 19, 2026 at 14:13 UTC. Non-positive and contextual checks: AlienVault OTX listed 1 community pulse reference (not vendor detections) on Mar 1, 2026 at 03:17 UTC. The separate external-blocklist snapshot contained no matches on Aug 8, 2026 at 06:20 UTC. Google Safe Browsing returned no flag on Mar 3, 2026 at 04:14 UTC. URLScan completed without a malicious verdict (score 0) on Jul 29, 2026 at 03:18 UTC. PhishStats returned no feed match on Mar 1, 2026 at 09:05 UTC.
HTTP 502 was recorded on Aug 7, 2026 at 01:13 UTC; content was unavailable. The recorded creation date for the domain is Feb 21, 2026. Registration preceded first observation by 5 days. At collection time, the hostname resolved to 188.114.96.3 on AS13335 (CLOUDFLARENET, US). The IP and ASN identify shared Cloudflare edge infrastructure; the origin server is not established by this address. DOM analysis on Jul 29, 2026 at 04:11 UTC returned 78/100. The evidence archive retains 3 visual captures from PhishDestroy, URLScan, and URLQuery. TLS metadata lists WE1 as the certificate issuer with validity through Apr 15, 2026.
The content indicators and 3 positive source findings support the current Google-themed credential phishing classification.
网络安全情报
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Cloudflare DNS | collaber.cfd |
malicious | Sinkholed |
| OpenDNS | collaber.cfd |
phishing | Phishing Block |
| DigiCert UltraDNS | collaber.cfd |
malicious | Sinkholed |
| Hagezi Threat Feed | collaber.cfd |
malicious | Sinkholed |
| DNS4EU | collaber.cfd |
malicious | Sinkholed |
威胁响应 Pipeline
公共封禁名单状态
已保存的截图
域名情报
技术细节DNS、SSL SAN、时间戳
SHORTDOT 域名区 · 公开证据
.cfd
ShortDot zone evidence
ShortDot zone evidence
The linked repository preserves daily zone observations across seven ShortDot-operated TLDs, including registration volume and abuse-related indicators. This registry context is supporting background and is not an independent detection for the domain in this report.
VirusTotal 分析
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。