msweblive[.]us
“Default Web Site Page”
证据摘要
This domain is flagged as a credential harvesting site actively masquerading as a legitimate web service. Infrastructure analysis reveals the use of a recently registered domain (June 22, 2026) designed to impersonate a known brand, likely targeting users through phishing emails or spoofed login portals. The domain resolves to IP 198.187.31.85, hosted on namecheap infrastructure, suggesting opportunistic abuse of a reputable hosting provider. Analysis indicates the domain employs generic phishing tactics to harvest credentials and sensitive input. Technical indicators include zero detections across 95 threat engines on VirusTotal, indicating low detection coverage despite suspicious behavior. The domain is registered via NAMECHEAP INC using namecheaphosting.com nameservers, and has not been flagged by Google Safe Browsing as of current assessment. No specific drainer kit or advanced tooling has been identified in open-source intelligence, suggesting a basic but effective campaign. Current status shows the domain remains active and accessible. Immediate response actions include blocking the IP 198.187.31.85 and domain msweblive.us at the network perimeter and reviewing proxy logs for prior exposure. The domain presents a moderate risk due to its recent activation and potential for user deception. Remediation priorities include takedown coordination with the hosting provider and updating browser blocklists. Users should avoid interacting with this domain and report any incidents involving credential submission from msweblive.us.
Data Coverage
威胁响应 Pipeline
阻止列表覆盖
监控中的外部数据源 10 个 · 已存快照 2026年8月13日
VirusTotal 分析
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。
检查任意域名
使用存储的阻止列表、WHOIS、DNS 和公共扫描证据进行威胁分析
立即扫描举报网络钓鱼
将可疑域名提交至我们的威胁数据库——保护社区
报告实时威胁动态
最近的网络钓鱼报告和观察到的可用性变化
监控