info-change[.]to
“404 Error”
证据摘要
Info-change.to is a phishing domain that has been flagged by 15 out of 95 vendors on VirusTotal. Despite its current offline status, the domain was actively used to exploit SSL trust, leveraging a certificate issued by Let's Encrypt. This tactic is commonly used to lend credibility to malicious sites, making them appear legitimate to unsuspecting users. The domain was registered through the Government of Kingdom of Tonga, a detail that highlights the diverse and often obscure registrars utilized by threat actors.
The hosting IP for info-change.to is located in Russia, under the organization DDOS-GUARD LTD, known for hosting various controversial sites. This choice of hosting provider suggests a deliberate attempt to shield the domain from swift takedown efforts. The domain's creation in August 2025 and its detection by PhishDestroy in November 2025 indicate a relatively short lifespan, typical of phishing campaigns designed to evade detection and maximize impact within a narrow time window.
The presence of info-change.to on PhishDestroy's blocklist underscores its malicious nature, despite the page currently displaying a 404 Error. The use of SSL certificates from Let's Encrypt is a common strategy among cybercriminals to enhance the perceived security of their phishing sites, thereby increasing the likelihood of deceiving users. The rapid detection and subsequent takedown of this domain demonstrate the effectiveness of collaborative efforts between security vendors and blocklist maintainers in mitigating phishing threats.
Data Coverage
网络安全情报
威胁响应 Pipeline
阻止列表覆盖
监控中的外部数据源 10 个 · 已存快照 2026年8月12日
VirusTotal 分析
网站性能分析
Google PageSpeed Insights — mobile performance audit of info-change.to · checked Mar 2, 2026
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。
检查任意域名
使用存储的阻止列表、WHOIS、DNS 和公共扫描证据进行威胁分析
立即扫描举报网络钓鱼
将可疑域名提交至我们的威胁数据库——保护社区
报告实时威胁动态
最近的网络钓鱼报告和观察到的可用性变化
监控