inboxlelo[.]shop
“Nitro Benefits and Features | DiscordNitro”
inboxlelo.shop — 内容不可用. 品牌冒充:Discord. 证据摘要: VirusTotal 7/93 (ADMINUSLabs, alphaMountain.ai, BitDefender, ESET, Fortinet); URLScan malicious verdict; PhishDestroy score 71/100.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
The domain inboxlelo.shop is currently listed as offline in threat intelligence feeds. It was registered on 21 February 2026 and resolves to the IPv4 address 62.60.226.105, which is allocated to AS214351 FEMO IT SOLUTIONS LIMITED and geolocated to Germany. Passive DNS data shows the domain pointing to this single IP, and no additional A records have been observed. The TLS certificate presented by the host is identified as grade E6, indicating a low‑trust certificate that lacks strong validation.
Reputation services have flagged the site; seven of ninety‑three scanners on VirusTotal reported detections, and the domain appears on one external blocklist. PhishDestroy has also added the host to its phishing blocklist. The only visible content retrieved by automated crawlers is a page whose title reads “Nitro Benefits and Features | DiscordNitro”, suggesting an attempt to impersonate Discord’s Nitro service, although the full page body has not been captured for analysis. No Safe Browsing or Open Threat Exchange entries are present in the supplied data.
The limited evidence indicates that the infrastructure is being used for a generic phishing campaign targeting Discord users, but the exact payload, credential‑stealing mechanism, and distribution vectors remain unknown. Defenders should block resolution to 62.60.226.105 at the network perimeter, add inboxlelo.shop to URL filtering and email security policies, and monitor for any traffic to the associated ASN. Continuous re‑scanning of the domain is advised to capture any changes in page content or additional malicious indicators.
威胁响应 Pipeline
公共封禁名单状态
VirusTotal 分析
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。