mx[.]campagnablu-contrasse[.]sbs
mx.campagnablu-contrasse.sbs — 内容不可用. 品牌冒充:Facebook. 证据摘要: VirusTotal 11/95 (Cluster25, CRDF, CyRadar, ESET, Fortinet); URLScan malicious verdict; Spamhaus DBL_PHISH; PhishDestroy score 83/100.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
The domain mx.campagnablu-contrasse.sbs was registered on February 21, 2026 and is currently listed as offline. Analysis shows that it resolves to the IP address 188.114.97.3, which belongs to the United States and is announced by ASN13335, operated by Cloudflare, Inc. The SSL certificate presented for the host is identified as WE1, indicating a publicly‑trusted certificate that does not inherently mitigate the observed malicious behavior. The domain appears on a single security blocklist and has been explicitly blocked by the PhishDestroy feed, confirming its association with phishing activity.
VirusTotal scans have yielded 11 positive detections out of 95 security vendors, demonstrating a moderate consensus among scanners that the domain is malicious. No additional contextual data such as page title, brand targeting, or kit attribution is available, leaving the exact phishing lure unknown. Given the combination of blocklist presence, PhishDestroy classification, and multi‑vendor detections, defenders should treat the domain as a confirmed phishing indicator.
Recommended mitigation steps include adding the domain to DNS deny‑list policies, blocking traffic to the associated IP address, and monitoring for any future resurrection of the host. Continuous re‑evaluation is advised in case the domain is re‑registered or the hosting environment changes, which could affect its risk posture.
威胁响应 Pipeline
公共封禁名单状态
已保存的截图
域名情报
技术细节DNS、SSL SAN、时间戳
SHORTDOT 域名区 · 公开证据
.sbs
ShortDot zone evidence
ShortDot zone evidence
The linked repository preserves daily zone observations across seven ShortDot-operated TLDs, including registration volume and abuse-related indicators. This registry context is supporting background and is not an independent detection for the domain in this report.
VirusTotal 分析
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。