kleinanzelgen[.]de[.]57561718[.]my
“Inhalt wird geladen”
kleinanzelgen.de.57561718.my — 内容不可用. 诈骗类型:Credential Phishing. 证据摘要: VirusTotal 14/91 (0xSI_f33d, alphaMountain.ai, BitDefender, Cluster25, CRDF); URLQuery 4 alerts; Spamhaus DBL_PHISH; PhishDestroy score 92/100. 注册商: Global Domain Group.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
This domain, kleinanzelgen.de.57561718.my, operates as an active credential harvesting phishing site designed to deceive users into submitting sensitive login information. Analysis indicates the site mimics legitimate authentication portals, likely targeting corporate or financial services, to capture usernames, passwords, and potentially multi-factor authentication codes. The infrastructure is configured to appear trustworthy, utilizing SSL encryption from Let's Encrypt to evade initial suspicion, while the underlying content is engineered to replicate the visual and functional elements of genuine platforms. Technical indicators confirm the malicious nature of this domain. It was registered on June 23, 2026, through Global Domain Group LLC, a registrar frequently associated with high-risk domains. The domain resolves to the IP address 34.111.179.208, hosted within Google LLC's AS396982 network, a common tactic to leverage reputable cloud infrastructure for phishing operations. Detection metrics further substantiate the threat: 13 out of 95 security vendors on VirusTotal flag the domain as malicious, and it appears on two independent security blocklists, including PhishDestroy and OpenPhish. The combination of recent registration, cloud-based hosting, and widespread detection underscores the high-risk classification. Users who have visited kleinanzelgen.de.57561718.my or entered credentials on the site should take immediate action to mitigate potential compromise. First, revoke any sessions or tokens associated with the credentials submitted, and reset passwords for all accounts where the same or similar credentials may have been reused. Enable multi-factor authentication on critical services if not already active. Monitor linked accounts for unauthorized activity, including financial transactions, email forwarding rules, or changes to security settings. If corporate credentials were exposed, report the incident to internal security teams to initiate an investigation and contain potential lateral movement. Finally, consider scanning affected devices for malware, as phishing sites may deploy additional payloads to maintain persistence.
网络安全情报
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| OpenDNS | kleinanzelgen.de.57561718.my |
phishing | Phishing Block |
| Hagezi Threat Feed | kleinanzelgen.de.57561718.my |
malicious | Sinkholed |
| DNS4EU | kleinanzelgen.de.57561718.my |
malicious | Sinkholed |
| Quad9 DNS | kleinanzelgen.de.57561718.my |
malicious | Sinkholed |
威胁响应 Pipeline
公共封禁名单状态
VirusTotal 分析
证据与外部报告
PD-20260625-A3BBA5 Recipient: abuse@globaldomaingroup.com 您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。