ny[.]pqpayfvr[.]cc
“pqpayfvr.cc | 520: Web server is returning an unknown error”
ny.pqpayfvr.cc — 内容不可用 (HTTP 502). 证据摘要: VirusTotal 6/91 (Forcepoint ThreatSeeker, Fortinet, Gridinsoft, LevelBlue, SOCRadar); PhishDestroy score 68/100. 注册商: Dominet (HK).
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
ny.pqpayfvr.cc was registered on June 12, 2026 through Dominet (HK) Limited and began resolving to the IPv4 address 188.114.96.3 shortly thereafter. The domain is currently flagged by the PhishDestroy blocklist and appears on one additional security blocklist, indicating that at least one trusted feed has categorized it as malicious. VirusTotal analysis shows that six of ninety‑one AV engines returned a positive detection for the domain, confirming the presence of known phishing indicators. The risk rating assigned by the reporting system is elevated, and the status is marked active, meaning the infrastructure is still reachable.
Infrastructure analysis reveals a single A‑record pointing to 188.114.96.3, a host that is often associated with fast‑flux and short‑lived malicious services. No TLS certificate details, HTTP status codes, or page‑title information are publicly available, so the content of the site remains unverified. However, the combination of recent registration, rapid deployment, multiple blocklist listings, and multi‑vendor detections strongly suggests that the domain is being used for generic phishing campaigns.
Defenders should add ny.pqpayfvr.cc to DNS‑based blocklists, enforce outbound filtering for the associated IP address, and monitor network traffic for any connections to the host. Continuous re‑scanning on VirusTotal or similar platforms is recommended to capture any evolution in the payload. Incident response teams should treat any credential submissions to this domain as compromised and initiate appropriate user notifications and credential resets.
网络安全情报
威胁响应 Pipeline
公共封禁名单状态
已保存的截图
域名情报
技术细节DNS、SSL SAN、时间戳
VirusTotal 分析
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。