dd1911a6e.scsewlm.cn
“视频 - Media App”
dd1911a6e.scsewlm.cn — 未验证. 证据摘要: VirusTotal 4/89 (Forcepoint ThreatSeeker, Gridinsoft, LevelBlue, SOCRadar); PhishDestroy score 71/100. 注册商: 阿里云计算有限公司(万网).
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
证据摘要
dd1911a6e.scsewlm.cn is a subdomain of scsewlm.cn. PhishDestroy first observed the hostname on Sep 9, 2026. The captured page title is “视频 - Media App”. Current evidence score: 71/100 (critical).
One source contains a positive finding: VirusTotal. VirusTotal recorded 4 detections among 89 engines: Forcepoint ThreatSeeker, Gridinsoft, LevelBlue, SOCRadar on Sep 9, 2026 at 14:49 UTC. Non-positive and contextual checks: The separate external-blocklist snapshot contained no matches on Sep 9, 2026 at 14:20 UTC. URLQuery recorded no positive detection; no observation timestamp was retained. Google Safe Browsing returned no flag on Sep 9, 2026 at 14:49 UTC. URLScan completed without a malicious verdict (score 0) on Sep 9, 2026 at 11:08 UTC.
The collector marked the hostname reachable on Sep 9, 2026 at 07:25 UTC, but did not retain the HTTP response code. Registration records for the registrable domain scsewlm.cn list 阿里云计算有限公司(万网) as the registrar and Dec 19, 2025 as the creation date. At collection time, the hostname resolved to 154.51.63.25 on AS135377 (UCLOUD-HK-AS-AP - UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED, HK). The recorded endpoint location is Kai Tak, HK. The stored server header is openresty. DOM analysis on Sep 9, 2026 at 10:22 UTC returned 71/100. The evidence archive retains 2 visual captures from PhishDestroy and URLScan. TLS metadata lists Let's Encrypt / YR2 as the certificate issuer with validity through Nov 29, 2026; checked Sep 9, 2026 at 10:02 UTC.
Stored content provides classification context, but only one source contains a positive finding. The stored fields do not identify an impersonated brand or victim interaction.
检测时间线
-
VirusTotal
3 → 4 (+1) (Added: SOCRadar)
-
VirusTotal
2 → 3 (+1) (Added: Forcepoint ThreatSeeker)
-
首次记录
首次存储值:可访问
威胁响应 Pipeline
公共封禁名单状态
已提交证据快照
- 已发送
- 台账记录
- 1
- 案件 ID
PD-20260909-6D199D
阻止列表覆盖
监控中的外部数据源 11 个 · 已存快照 2026年9月9日
VirusTotal 分析
证据与外部报告
PD-20260909-6D199D Recipient: abuse@cogentco.com 您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。