impressengineering[.]co[.]ke
“Home - Impress Engineering”
证据摘要
The domain impressengineering.co.ke is currently active and resolves to the IPv4 address 46.165.235.143, which is advertised as part of AS28753 Leaseweb Deutschland GmbH located in Germany. The site returns HTTP 200 and presents a page title of “Home - Impress Engineering”. Technical fingerprinting reveals a WordPress stack backed by MySQL and PHP, served through LiteSpeed, and includes front‑end libraries such as Swiper, jQuery, jQuery Migrate and Font Awesome. The domain was registered on 8 November 2023 through HostPinnacle Cloud Limited and uses a Let’s Encrypt R12 certificate, indicating that TLS is properly configured.
VirusTotal records show that two of ninety‑three scanning engines have flagged the domain, and the domain is listed on two public blocklists, specifically PhishDestroy and ScamSniffer. Both blocklists classify the activity as banking phishing, which aligns with the supplied scam type label. Nameservers rs51‑rs54.rcnoc.com are associated with the same hosting provider. No additional intelligence on the page content or the specific credential‑harvesting mechanism is presently available, so the exact phishing lure remains unconfirmed.
However, the combination of a recent registration, active hosting, a valid TLS certificate, and detection by multiple security vendors and blocklists strongly suggests a malicious intent aimed at credential theft. Defensive teams should continue to block the domain at network perimeters, add the IP address 46.165.235.143 to deny‑list rules, and monitor DNS queries for the associated nameservers. Organizations that process banking credentials should treat any communications from this domain as hostile and educate users to avoid interacting with the site. Continuous re‑scanning on VirusTotal and inclusion in threat‑intel feeds are recommended to capture any future changes in the payload or hosting infrastructure.
Data Coverage
威胁响应 Pipeline
阻止列表覆盖
监控中的外部数据源 10 个 · 已存快照 2026年8月11日
检测时间线
-
域名状态
可访问 → 无法访问
-
Cloudflare Radar
已存储 Cloudflare Radar 扫描 · 打开扫描
VirusTotal 分析
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。
检查任意域名
使用存储的阻止列表、WHOIS、DNS 和公共扫描证据进行威胁分析
立即扫描举报网络钓鱼
将可疑域名提交至我们的威胁数据库——保护社区
报告实时威胁动态
最近的网络钓鱼报告和观察到的可用性变化
监控