dune-bag-pl[.]shop
“Saway Partner | Oficjalny Partner Promocyjny | Nowoczesny Marketing”
dune-bag-pl.shop — 未验证. 证据摘要: VirusTotal 19/90 (alphaMountain.ai, BitDefender, Chong Lua Dao, CRDF, CyRadar); URLQuery 5 alerts; URLScan capture; Spamhaus DBL_PHISH; PhishDestroy score 95/100.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
PhishDestroy first observed dune-bag-pl.shop on Sep 5, 2026. The captured page title is “Saway Partner | Oficjalny Partner Promocyjny | Nowoczesny Marketing”. Current evidence score: 95/100 (critical).
Positive findings are stored from 3 sources: VirusTotal, Spamhaus DBL, and URLQuery. VirusTotal recorded 19 detections among 90 engines: alphaMountain.ai, BitDefender, Chong Lua Dao, CRDF, CyRadar, ESET, Forcepoint ThreatSeeker, Fortinet, G-Data, Gridinsoft, Kaspersky, LevelBlue, Lionic, PREBYTES, Seclookup, SOCRadar, Sophos, VIPRE, Webroot on Sep 5, 2026 at 22:57 UTC. Spamhaus DBL: DBL_PHISH on Sep 5, 2026 at 22:30 UTC. URLQuery recorded 5 threat-system alerts on Sep 5, 2026 at 19:25 UTC. Non-positive and contextual checks: AlienVault OTX listed 5 community pulse references (not vendor detections) on Sep 5, 2026 at 22:58 UTC. The separate external-blocklist snapshot contained no matches on Sep 5, 2026 at 22:20 UTC. Google Safe Browsing returned no flag on Sep 5, 2026 at 22:57 UTC. URLScan captured the page on Sep 5, 2026 at 19:21 UTC.
The collector marked the hostname reachable on Sep 5, 2026 at 19:21 UTC, but did not retain the HTTP response code. At collection time, the hostname resolved to 104.18.71.116 on AS13335 (Cloudflare, Inc.). The IP and ASN identify shared Cloudflare edge infrastructure; the origin server is not established by this address. The stored server header is nginx. The evidence archive retains 4 visual captures from PhishDestroy, URLScan, and URLQuery. TLS metadata lists Google Trust Services as the certificate issuer with validity through Oct 8, 2026; checked Sep 5, 2026 at 22:02 UTC.
The content indicators and 3 positive source findings support the current phishing classification. The stored fields do not identify an impersonated brand or victim interaction.
网络安全情报
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| OpenDNS | dune-bag-pl.shop |
phishing | Phishing Block |
| Cloudflare DNS | dune-bag-pl.shop |
malicious | Sinkholed |
| Quad9 DNS | dune-bag-pl.shop |
malicious | Sinkholed |
| DigiCert UltraDNS | dune-bag-pl.shop |
malicious | Sinkholed |
| DNS4EU | dune-bag-pl.shop |
malicious | Sinkholed |
威胁响应 Pipeline
公共封禁名单状态
所用技术 · 2 identified
Nginx is a web server that can also be used as a reverse proxy, load balancer, mail proxy and HTTP cache.
nginx.org 置信度 100%HTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org 置信度 100%VirusTotal 分析
网站性能分析
Google PageSpeed Insights — mobile performance audit of dune-bag-pl.shop · checked Sep 5, 2026
证据与外部报告
PD-20260905-A233DF Recipient: abuse@spaceship.com 您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。