medve-law[.]mssg[.]me
“Михаил Медведев”
medve-law.mssg.me — 未验证. 诈骗类型:Credential Phishing. 证据摘要: VirusTotal 1/91 (Chong Lua Dao); PhishDestroy score 55/100. 注册商: Key-Systems.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
PhishDestroy identifies medve-law.mssg.me as an active credential theft domain impersonating the public persona of Mikhail Medvedev, the former Prime Minister of Russia. The site leverages the namesake of a prominent political figure to deceive visitors into submitting sensitive login credentials under the guise of official or professional correspondence. As of the latest assessment, the domain remains live and is actively collecting user data under false pretenses. Credential theft via brand impersonation represents a high-risk tactic frequently deployed to harvest credentials for financial fraud, espionage, or further social engineering campaigns. Users interacting with this domain risk immediate compromise of account credentials and personal information.
This domain was flagged by zero of 95 VirusTotal vendors as of the last scan on the provided seed 73a6f8. It resolves to IP address 172.67.75.137, uses a Cloudflare SSL certificate, and is registered through Key-Systems GmbH. The domain was created on January 24, 2017. It has not been listed on any public blocklists at this time, indicating a stealth implantation likely intended for targeted campaigns rather than large-scale abuse. The combination of a legitimate registrar, long domain age, and clean VirusTotal score suggests sophisticated evasion techniques to bypass automated detection systems.
medve-law.mssg.me is currently active and evaluated as a credible threat under ongoing investigation. Given the demonstrated use of brand impersonation for credential theft and the absence of current blocklist coverage, immediate action is required. Users should avoid accessing or submitting any data to this domain. Security teams are advised to block the domain at the network level, inspect DNS resolution logs for historical contact, and monitor endpoints for signs of credential misuse. Implementing administrative controls to restrict access to the domain via corporate proxies or firewalls is strongly recommended.
威胁响应 Pipeline
公共封禁名单状态
所用技术 · 6 identified
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
Tag management system for deploying marketing and analytics tags.
tagmanager.google.comWeb analytics service tracking website traffic and user behavior.
marketingplatform.google.comConversion-tracking pixel by Meta — logs page views and custom events to Facebook/Instagram ad accounts.
www.facebook.comPerformance monitoring tool that measures website speed from real users.
www.cloudflare.comWeb infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comVirusTotal 分析
网站性能分析
Google PageSpeed Insights — mobile performance audit of medve-law.mssg.me · checked Apr 15, 2026
网站配置分析
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。