emailanalytics[.]com[.]ua
emailanalytics.com.ua 网络钓鱼与安全检查
“emailanalytics.com.ua”
emailanalytics.com.ua — 内容不可用 (HTTP 502). 证据摘要: VirusTotal 19/91 (ADMINUSLabs, alphaMountain.ai, ArcSight Threat Intelligence, BitDefender, Certego); CF Radar malicious; PhishDestroy score 100/100. 注册商: ТОВ "ОН-ЛАЙН".
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
The domain emailanalytics.com.ua is currently active and has been observed in a phishing context. Registration data shows it was created on September 23, 2025 by the Ukrainian entity ТОВ "ОН-ЛАЙН" and is hosted on the IP address 185.86.79.95. DNS resolution is served by Cloudflare name servers ines.ns.cloudflare.com and yew.ns.cloudflare.com, indicating the use of a reputable CDN for concealment and resilience. VirusTotal analysis reports that 19 of 91 security vendors flag the domain as malicious, confirming a consensus of detection across multiple scanning engines.
The domain is listed on a single security blocklist and is explicitly blocked by the PhishDestroy service, demonstrating that at least one dedicated anti‑phishing platform has taken mitigation action. No public evidence has been provided regarding Safe Browsing status, Open Threat Exchange (OTX) listings, SSL certificate details, HTTP response codes, trust‑score metrics, page title, or additional evidence links, leaving those aspects unverified at this time. The lack of publicly disclosed page content or brand targeting means that the exact phishing lure cannot be confirmed, but the classification as generic phishing is supported by the detection count and blocklist presence. Defenders should add emailanalytics.com.ua to domain‑based blocklists across email gateways, web proxies, and endpoint protection solutions.
Continuous monitoring of the IP address 185.86.79.95 for any new malicious activity is advised, as well as periodic re‑scanning with VirusTotal or similar multi‑engine services to capture any changes in detection posture. Organizations using Cloudflare’s DNS filtering can consider adding the domain to their deny list. Incident response teams should treat any communications originating from or referencing this domain as potentially fraudulent and investigate associated user reports accordingly.
网络安全情报
威胁响应 Pipeline
公共封禁名单状态
VirusTotal 分析
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。