pip2pactivepi[.]com
pip2pactivepi.com 网络钓鱼与安全检查
“mamma”
pip2pactivepi.com — 内容不可用 (HTTP 502). 品牌冒充:Facebook. 证据摘要: VirusTotal 13/93 (alphaMountain.ai, BitDefender, Chong Lua Dao, CyRadar, ESET); PhishDestroy score 89/100.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
The domain pip2pactivepi.com is identified as a credential theft site currently impersonating the Mamma search engine. Analysis indicates the domain is offline, though it previously hosted active malicious infrastructure designed to harvest user credentials. The threat type is classified as credential theft, targeting unsuspecting users through deceptive search engine mimicry. Infrastructure analysis reveals the domain was created on February 21, 2026, an anomalous future date suggesting potential registrar manipulation or data obfuscation. It resolves to the IP address 198.251.83.50, hosted on AS53667 FranTech Solutions, a provider frequently associated with bulletproof hosting environments. The domain is flagged by 13 of 95 security vendors on VirusTotal, indicating broad detection as malicious. It appears on one security blocklist and is associated with an SSL certificate labeled E7, which may indicate a low-trust or self-signed certificate. The page title, mamma, aligns with the impersonated brand, reinforcing the credential theft objective. Current status confirms the domain is offline, reducing immediate risk to end users. However, the infrastructure remains a potential threat if reactivated. Organizations and individuals are advised to block the domain and IP address at the network level, monitor for related indicators of compromise, and educate users on recognizing credential theft tactics. Security teams should review logs for connections to 198.251.83.50 and investigate any associated SSL certificate fingerprints. Proactive measures include implementing multi-factor authentication and enforcing strict domain validation policies to mitigate future credential theft risks.
威胁响应 Pipeline
公共封禁名单状态
所用技术 · 2 identified
Server-side scripting language designed for web development.
Most widely used open-source HTTP server software.
VirusTotal 分析
网站性能分析
Google PageSpeed Insights — mobile performance audit of pip2pactivepi.com · checked Mar 2, 2026
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。