itrustcapital-loginn[.]webflow[.]io
“iTrustcapital login | Sign In”
已存储的观测记录
观测到的标题差异
证据摘要
The domain itrustcapital-loginn.webflow.io was registered through MarkMonitor, Inc. and resolves to the Cloudflare address 104.18.36.248, an IP located in the United States and announced by ASN AS13335 (Cloudflare, Inc.). The site presented a TLS certificate issued by Google Trust Services under the WE1 label, confirming the use of standard HTTPS termination. Google Safe Browsing identified the domain as a social engineering vector, and the phishing kit was subsequently blocked by PhishDestroy and listed on a single security blocklist. VirusTotal analysis shows that 15 of 95 scanned security vendors flagged the domain, indicating moderate detection consensus.
The observed page title, "iTrustcapital login | Sign In," aligns with the declared scam type of credential phishing, targeting users who may attempt to enter login credentials for iTrustcapital. Infrastructure scans revealed the use of Cloudflare services and HTTP/3 protocol, with nameservers journey.ns.cloudflare.com and lamar.ns.cloudflare.com. The domain was created on May 08, 2013, but the current HTTP response is a 404 status, and the overall status is reported as offline as of the July 23, 2026 report date.
While the site is presently inactive, the combination of registrar data, hosting details, SSL issuance, Safe Browsing flag, blocklist entry, and multi‑vendor detections provides a clear indication of malicious intent. Defenders should continue to block the domain at DNS and proxy layers, monitor for any re‑activation or similar sub‑domains, and incorporate the observed indicators—IP address, nameservers, certificate issuer, and page title—into threat‑intel feeds. Ongoing vigilance is advised because the infrastructure (Cloudflare front‑end) could be repurposed for future credential‑theft campaigns.
Data Coverage
威胁响应 Pipeline
阻止列表覆盖
监控中的外部数据源 10 个 · 已存快照 2026年8月12日
检测时间线
-
域名状态
可访问 → 无法访问
-
Cloudflare Radar
已存储 Cloudflare Radar 扫描 · 打开扫描
技术
识别出 2 项高置信度技术
VirusTotal 分析
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。
检查任意域名
使用存储的阻止列表、WHOIS、DNS 和公共扫描证据进行威胁分析
立即扫描举报网络钓鱼
将可疑域名提交至我们的威胁数据库——保护社区
报告实时威胁动态
最近的网络钓鱼报告和观察到的可用性变化
监控