site-language[.]us
“FinStore UK”
证据摘要
On July 22, 2026, investigators observed that the domain site-language.us was registered on March 30 2026 through Web Commerce Communications Limited dba WebNic.cc. The domain resolves to the Cloudflare‑owned address 172.67.215.20 and uses the Cloudflare nameservers coleman.ns.cloudflare.com and mariah.ns.cloudflare.com, placing the infrastructure in Canada under Cloudflare, Inc. No SSL/TLS certificate was presented, indicating the site operated without HTTPS encryption. Page metadata revealed the title “FinStore UK,” and the intelligence feed categorizes the site as a “Fake Exchange” scam, suggesting it attempted to masquerade as a financial trading platform. Technical fingerprints show the use of Material Design Lite, Bootstrap, Cloudflare Browser Insights, and HTTP/3, all typical of a quickly assembled front‑end.
VirusTotal recorded a single positive detection out of 94 scanning engines, while Gridinsoft assigned a trust score of 0 / 100. The domain appears on three public blocklists and is actively blocked by PhishDestroy, MetaMask, and SEAL. Current status is offline, but the presence on blocklists indicates prior malicious activity.
Uncertainties remain regarding the exact payload or credential‑harvesting mechanisms employed, as the site content has not been captured and the lack of SSL prevents inspection of traffic. Defenders should therefore pre‑emptively deny resolution of site-language.us at the DNS layer, enforce URL filtering based on the known blocklist identifiers, and monitor Cloudflare‑associated IP 172.67.215.20 for any resurgence of malicious services. Security teams should also alert end‑users that communications referencing “FinStore UK” may be fraudulent, and incorporate the domain indicator into threat‑intel feeds to improve detection across endpoint and network controls.
Data Coverage
威胁响应 Pipeline
阻止列表覆盖
监控中的外部数据源 10 个 · 已存快照 2026年8月12日
取证情报
VirusTotal 分析
网站性能分析
Google PageSpeed Insights — mobile performance audit of site-language.us · checked Mar 30, 2026
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。
检查任意域名
使用存储的阻止列表、WHOIS、DNS 和公共扫描证据进行威胁分析
立即扫描举报网络钓鱼
将可疑域名提交至我们的威胁数据库——保护社区
报告实时威胁动态
最近的网络钓鱼报告和观察到的可用性变化
监控