mail[.]mewe-fintech[.]com
“Mewe Fintech | Trading with a reliable broker.”
mail.mewe-fintech.com — 内容不可用 (HTTP 502). 品牌冒充:Base. 证据摘要: VirusTotal 10/93 (alphaMountain.ai, BitDefender, CyRadar, Fortinet, G-Data); Spamhaus DBL_SPAM; PhishDestroy score 80/100.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
Analysis shows that mail.mewe-fintech.com was registered on February 21, 2026 and is currently taken offline. The domain resolves to IP address 198.12.80.250, which is hosted in the United States under AS36352 (HostPapa). An SSL certificate with rating R13 is present, indicating a typical commercial certificate without extended validation. The page title returned by the site, "Mewe Fintech | Trading with a reliable broker," suggests the domain is attempting to masquerade as a financial services provider named Mewe Fintech.
Ten of ninety‑three security vendors on VirusTotal flagged the domain, providing independent confirmation of malicious intent. The domain is listed on a single security blocklist and has been actively blocked by the PhishDestroy service, reinforcing the assessment of elevated risk. The threat type is classified as generic phishing, consistent with the observed impersonation of a broker‑related brand. Defenders should continue to block DNS resolution to 198.12.80.250, enforce URL filtering for the full hostname, and monitor for any resurgence of the domain on additional blocklists.
Because the site is offline, immediate infection vectors are unlikely, but the infrastructure—particularly the shared hosting provider—may host other malicious actors. Continuous observation of HostPapa‑associated IP ranges and periodic re‑scans of the domain are recommended to detect any re‑activation. The evidence base is limited to registration metadata, SSL details, VirusTotal detections, and blocklist entries; no content analysis beyond the page title is available, so further investigation should focus on network‑level indicators and potential reuse of the hosting environment.
威胁响应 Pipeline
公共封禁名单状态
VirusTotal 分析
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。