login[.]thefoundation[.]es
login.thefoundation.es — 内容不可用. 品牌冒充:MetaMask. 证据摘要: VirusTotal 13/91 (alphaMountain.ai, BitDefender, Chong Lua Dao, CRDF, CyRadar); 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 89/100.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
The domain login.thefoundation.es is currently classified as an active credential phishing infrastructure with a high risk rating. Analysis of public threat feeds shows the site has been blocked by multiple anti‑phishing services, including PhishDestroy, MetaMask, and SEAL, indicating that the domain is actively used to harvest credentials. VirusTotal reports that 13 of 91 scanning engines flag the domain as malicious, providing vendor‑level corroboration of its nefarious purpose.
Additionally, the domain appears on three independent security blocklists, further confirming its reputation as a phishing host. No public information on the registrar, hosting IP, SSL certificate, HTTP response code, or Safe Browsing status is available at this time, and the page title has not been disclosed in the shared intelligence. Consequently, defenders should treat any traffic to login.thefoundation.es as hostile.
Recommended mitigation steps include adding the domain to local deny lists, updating web‑filter rules to block both HTTP and HTTPS connections, and monitoring DNS logs for queries to the domain. Incident response teams should also consider correlating authentication failures and credential‑theft alerts with activity on this domain, as its presence in multiple blocklists suggests it is part of an ongoing campaign. Continuous re‑evaluation is advised, as additional indicators such as IP attribution or SSL fingerprint may emerge in future threat feeds.
网络安全情报
威胁响应 Pipeline
公共封禁名单状态
域名情报
技术细节DNS、SSL SAN、时间戳
VirusTotal 分析
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。