footbalfun[.]xyz
footbalfun.xyz — 内容不可用. 证据摘要: VirusTotal 3/93 (alphaMountain.ai, Forcepoint ThreatSeeker, SOCRadar); PhishDestroy score 65/100.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
The domain footbalfun.xyz was registered on February 21, 2026 and is currently listed as offline. Threat intelligence sources have identified it as a generic phishing site. VirusTotal scans show that three of ninety‑three security vendors flagged the domain as malicious, indicating a non‑trivial detection rate across independent engines. The domain is blocked by the PhishDestroy service and appears on one external security blocklist, reinforcing its classification as a phishing vector.
DNS resolution points to the IP address 188.114.97.3, which is hosted by Cloudflare, Inc. (AS13335) and geolocated to the United States. The SSL certificate presented is identified as WE1, but no further certificate details (such as issuer or validity period) are disclosed. A Gridinsoft trust score of 0 out of 100 was recorded, suggesting that the hosting environment is deemed highly untrustworthy by that vendor. No additional metadata such as page title, brand targeting, or kit information is available, leaving the exact impersonated service unknown.
Defenders should add footbalfun.xyz to internal deny lists, monitor DNS queries for the associated IP address, and ensure that any endpoint protection solutions incorporate the three vendor detections from VirusTotal. Continuous watching of Cloudflare‑hosted IP ranges for similar activity is advisable, as the infrastructure may be reused for future phishing campaigns. Since the site is offline, immediate takedown is not required, but proactive blocking will prevent potential re‑activation or reuse of the same domain or hosting assets.
威胁响应 Pipeline
公共封禁名单状态
VirusTotal 分析
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。