sap2524e7e[.]cc
“sap2524e7e.cc”
证据摘要
This domain is flagged as a credential harvesting phishing endpoint with an elevated risk level. Analysis indicates the infrastructure was established specifically for malicious activity, targeting users through fraudulent login or data submission pages. The domain exhibits multiple high-risk indicators consistent with phishing campaigns designed to capture sensitive authentication details or personal information. Infrastructure analysis reveals the domain sap2524e7e.cc was registered on July 26, 2025, through GoDaddy.com, LLC. It currently resolves to the IP address 154.38.99.2, hosted on AS140224 (Nebula Global LLC) in Hong Kong. The domain lacks an SSL certificate, increasing the likelihood of interception or manipulation during data transmission. Security vendor detections on VirusTotal report 16/95 flags, while the domain appears on two distinct security blocklists: PhishDestroy and PhishingDB. The page title matches the domain name exactly, a common tactic to avoid detection by mimicking legitimate or generic identifiers. Mitigation requires immediate blocking of the domain and its associated IP address across all network security controls. Organizations should implement DNS-based filtering to prevent resolution of sap2524e7e.cc and monitor for any attempts to access the IP 154.38.99.2 from internal systems. Endpoint protection should be updated to detect and quarantine any artifacts linked to this campaign, including phishing pages or scripts hosted on the domain. Security teams are advised to review logs for connections to the domain or IP since its creation date and investigate any successful interactions for potential credential compromise or data exfiltration.
Data Coverage
网络安全情报
威胁响应 Pipeline
阻止列表覆盖
监控中的外部数据源 10 个 · 已存快照 2026年8月13日
检测时间线
VirusTotal 分析
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。
检查任意域名
使用存储的阻止列表、WHOIS、DNS 和公共扫描证据进行威胁分析
立即扫描举报网络钓鱼
将可疑域名提交至我们的威胁数据库——保护社区
报告实时威胁动态
最近的网络钓鱼报告和观察到的可用性变化
监控