swissborgloginev[.]webflow[.]io
“SwissBorg Login - Sign In @SwissBorg Account”
证据摘要
On August 07, 2026 the domain swissborgloginev.webflow.io was observed being used in a credential phishing campaign targeting users of the SwissBorg platform. The domain is registered through the Webflow hosting service, which provides rapid site deployment and automatic TLS. DNS resolution points to the IP address 104.18.36.248, an address owned by Cloudflare, indicating the infrastructure is leveraging a shared CDN edge node. The site has been added to two independent phishing blocklists, PhishDestroy and OpenPhish, and both services currently list the domain as blocked.
VirusTotal analysis shows that 17 of 91 security vendors submitted a detection, confirming that a significant minority of scanners recognize malicious behavior. The domain appears on two broader security blocklists, reinforcing the consensus that it is being used for malicious purposes. No additional public intelligence such as page title, SSL certificate details, or HTTP response codes has been disclosed, leaving the exact content of the landing page unverified. The lack of further forensic artifacts means that attribution of the operators and the specific phishing kit remains uncertain.
Defenders should block network traffic to the domain and its resolved IP, add the host to local and cloud‑based URL filtering lists, and monitor for credential submissions that match SwissBorg login patterns. Continuous monitoring of the IP reputation and periodic rescans on VirusTotal are recommended, as the detection count may evolve. Users should be warned that any login prompt originating from swissborgloginev.webflow.io is likely fraudulent and should be ignored.
Data Coverage
网络安全情报
威胁响应 Pipeline
阻止列表覆盖
监控中的外部数据源 10 个 · 已存快照 2026年8月13日
检测时间线
-
首次记录
首次存储值:可访问
技术
识别出 3 项高置信度技术
VirusTotal 分析
存档证据
网站性能分析
Google PageSpeed Insights — mobile performance audit of swissborgloginev.webflow.io · checked Aug 7, 2026
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。
检查任意域名
使用存储的阻止列表、WHOIS、DNS 和公共扫描证据进行威胁分析
立即扫描举报网络钓鱼
将可疑域名提交至我们的威胁数据库——保护社区
报告实时威胁动态
最近的网络钓鱼报告和观察到的可用性变化
监控