pb-coach[.]crabdance[.]com
“Apache2 Ubuntu Default Page: It works”
pb-coach.crabdance.com — 可达 · 访问受限 (HTTP 403). 品牌冒充:MetaMask; 诈骗类型:Credential Phishing. 证据摘要: VirusTotal 8/91 (alphaMountain.ai, CyRadar, Dr.Web, Forcepoint ThreatSeeker, Fortinet); Spamhaus DBL_PHISH; 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 85/100. 注册商: eNom.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
The domain pb-coach.crabdance.com was registered on June 08, 2026. Within days it appeared on three public security blocklists and is actively blocked by the PhishDestroy, MetaMask, and SEAL filtering services. VirusTotal analysis shows that eight of ninety‑one scanning engines flagged the domain as malicious, indicating a consensus of concern among multiple vendors. DNS resolution points to the loopback address 127.0.0.2, which is atypical for legitimate web hosting and suggests a deliberate attempt to avoid exposure of a real backend server.
No SSL certificate information, HTTP response codes, or page title data are currently available, limiting the ability to confirm the content served by the site. The lack of publicly disclosed registrar details, ASN, or geographic hosting data further obscures the infrastructure footprint. Defenders encountering traffic to pb‑coach.crabdance.com should treat the connection as high‑confidence malicious, block the domain at perimeter firewalls, DNS resolvers, and endpoint web filters, and incorporate the indicator into intrusion detection signatures.
Continuous monitoring of threat‑intel feeds for additional detections, updates to the blocklist status, and correlation with internal logs for any attempted credential submission to the domain are recommended. Because the site resolves to a loopback address, any attempted connections will fail, but the presence of the domain in phishing‑specific blocklists suggests it may be used as a lure in emails or other social‑engineering vectors. Organizations should educate users about the suspicious nature of unsolicited communications referencing “pb‑coach” or related terms and enforce multi‑factor authentication to mitigate credential theft risk.
网络安全情报
威胁响应 Pipeline
公共封禁名单状态
域名情报
技术细节DNS、SSL SAN、时间戳
ICANN OVERSIGHT
Registration: crabdance.com
认证和 RAA 背景
认证和 RAA 背景
Registrar accreditation and DNS abuse obligations
For the registrable domain crabdance.com behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
VirusTotal 分析
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。