epostcaribbean[.]cwy[.]teq[.]mybluehost[.]me
“顺丰速运”
epostcaribbean.cwy.teq.mybluehost.me — 内容不可用. 证据摘要: VirusTotal 8/95 (ADMINUSLabs, alphaMountain.ai, Chong Lua Dao, CyRadar, Fortinet); CF Radar malicious; PhishDestroy score 79/100. 注册商: Domain.com - Network S….
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
Analysis of epostcaribbean.cwy.teq.mybluehost.me shows a clear phishing profile despite the site being taken offline at the time of review. The domain was registered on October 5, 2016 through Domain.com – Network Solutions, LLC, and is served by Apache HTTP Server on a hosting environment that resolves to IP address 162.214.190.13. The IP is allocated to Unified Layer (AS46606) and resides in the United States. The domain’s DNS configuration uses the authoritative nameservers ns1.mybluehost.me and ns2.mybluehost.me, both operated by the MyBluehost hosting platform. An SSL certificate issued by Let’s Encrypt (R13) is present, indicating that the site attempted to present encrypted communications, a common tactic used to increase victim trust.
The page title returned by the server is "顺丰速运," a reference to a well‑known logistics brand, but no further content analysis is available because the site is offline. Reputation services record extremely low trust scores: Scamadviser rates the domain 1 / 100 and Gridinsoft assigns a score of 0 / 100, reinforcing the malicious assessment. The domain appears on a single security blocklist and has been explicitly blocked by PhishDestroy. VirusTotal scanning identified eight detections out of ninety‑five antivirus engines, providing independent confirmation of malicious behavior.
For defenders, the immediate recommendation is to add the IP address 162.214.190.13 to network deny lists and to block any future DNS resolutions of epostcaribbean.cwy.teq.mybluehost.me. Monitoring for re‑use of the underlying hosting infrastructure or similar domain patterns is advisable, as threat actors often recycle assets after takedown. Continuous probing of the associated nameservers for new subdomains or redeployments should be incorporated into threat‑intel feeds. The combination of low trust scores, multiple vendor detections, and active blocklist entries substantiates a high confidence classification of this domain as a phishing resource.
安全信号
网络安全情报
威胁响应 Pipeline
公共封禁名单状态
所用技术 · 1 identified
VirusTotal 分析
存档证据
网站性能分析
Google PageSpeed Insights — mobile performance audit of epostcaribbean.cwy.teq.mybluehost.me · checked Mar 6, 2026
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。