s[.]team-cxv[.]pro
s.team-cxv.pro — 内容不可用 (HTTP 502). 证据摘要: VirusTotal 7/93 (CRDF, ESET, Fortinet, Gridinsoft, SOCRadar); PhishDestroy score 76/100.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
Analysis of the domain s.team-cxv.pro indicates that it was registered on February 21, 2026 and subsequently taken offline prior to the report date of July 24, 2026. The domain resolves to the IPv4 address 38.89.142.175, which is allocated to Cogent Communications, LLC (AS174) and geolocated to Singapore. Threat intelligence feeds have flagged the domain as malicious: seven of ninety‑three security vendors on VirusTotal reported a detection, and the site is listed on a single security blocklist. Additional reputation services assign extremely low trust scores, with Gridinsoft reporting 0 out of 100 and Scamadviser rating the domain at 1 out of 100.
The SSL certificate associated with the domain carries an R10 rating, suggesting a weak or untrusted certificate. PhishDestroy has actively blocked the domain, confirming its use in phishing campaigns. No public page title, brand target, or kit information is available, and the exact content of the hosted site has not been captured.
The combination of low trust scores, multiple vendor detections, and blocklist presence classifies the infrastructure as elevated‑risk generic phishing. Defenders should continue to block the domain at network perimeter devices, update URL filtering and DNS sinkhole lists, and monitor the associated IP address for any re‑activation. Incident responders should also consider the IP’s ASN (AS174) when assessing broader campaign activity, as Cogent‑hosted infrastructure is frequently leveraged for short‑lived phishing sites.
威胁响应 Pipeline
公共封禁名单状态
取证情报
VirusTotal 分析
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。