pc[.]executevip[.]vip
“Learnfx”
On July 25 2026, analysis of the domain pc.executevip.vip identified it as an elevated‑risk phishing infrastructure that has been taken offline. The domain was registered on 9 June 2025 through Gname.com Pte. Ltd. and resolves to 188.114.96.3, an address owned by Cloudflare (AS13335, United States). Both authoritative nameservers—autumn.ns.cloudflare.com and cory.ns.cloudflare.com—are Cloudflare‑managed, indicating the attacker leveraged Cloudflare’s CDN and DDoS protection services. HTTP traffic was observed over HTTP/3 and the site was built with Vue.js, confirming a modern JavaScript front‑end framework. The page title returned by the server is “Learnfx”, but no further content has been captured because the site is currently offline.
Reputation services consistently flag the host. Gridinsoft assigns a trust score of 0/100, effectively marking the site as malicious. VirusTotal reports that 7 out of 94 scanned engines flagged the domain, reinforcing the suspicion. Independent blocklists have listed the domain on three separate entries, and commercial phishing mitigation platforms PhishDestroy, MetaMask, and SEAL have already blocked access to the site. No public SSL certificate details are available, and the HTTP status code at the time of collection was not recorded due to the offline state.
The evidence points to a deliberately short‑lived phishing operation that likely used a generic “Learnfx” landing page to lure victims, possibly as part of a credential‑ harvesting campaign. However, the exact target brand or credential collection mechanism remains unknown because the page content has not been archived. Analysts should continue to monitor the IP address 188.114.96.3 for any re‑use by other malicious domains, and enforce blocking of pc.executevip.vip at network perimeters and endpoint filters.
威胁响应 Pipeline
阻止列表覆盖
10 个来源 · 于 2026年8月9日 同步
检测时间线
按时间顺序显示已存储的观测记录。
-
VirusTotal
VirusTotal:0 → 3
已保存的截图
域名情报
技术详情DNS、SSL SAN、时间戳
ICANN OVERSIGHT
Registration: executevip.vip
认证和 RAA 背景
认证和 RAA 背景
Registrar accreditation and DNS abuse obligations
For the registrable domain executevip.vip behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
VirusTotal 分析
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。
检查任意域名
使用存储的阻止列表、WHOIS、DNS 和公共扫描证据进行威胁分析
立即扫描举报网络钓鱼
将可疑域名提交至我们的威胁数据库——保护社区
报告实时威胁动态
最近的网络钓鱼报告和观察到的可用性变化
监控