tfjg-rjgu-egji-zjgi-orjg-rngj[.]netlify[.]app
“Connect & Unlock”
tfjg-rjgu-egji-zjgi-orjg-rngj.netlify.app — 内容不可用. 品牌冒充:["trezor"]; 诈骗类型:Seed Phrase Theft. 证据摘要: VirusTotal 15/95 (ADMINUSLabs, Criminal IP, alphaMountain.ai, BitDefender, CRDF); 3 external blocklist matches (Polkadot, Enkrypt, Codeesura); CF Radar malicious; PhishDestroy score 95/100. 注册商: Netlify.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
The domain tfjg-rjgu-egji-zjgi-orjg-rngj.netlify.app is currently flagged as a high‑risk phishing site. Infrastructure analysis shows the domain resolves to the IP address 63.176.8.218, which belongs to Amazon.com, Inc. (AS16509) and is geolocated in Germany. The hosting environment is identified as Netlify, with HSTS enabled, indicating the site was served over HTTPS. The SSL certificate presented is a DigiCert Global G2 TLS RSA SHA256 2020 CA1 certificate issued by DigiCert Inc., confirming a valid TLS chain but offering no assurance of legitimacy. HTTP probing returned a 404 status, suggesting the page is no longer publicly reachable; the domain’s status is listed as offline.
The page title that was observed when the site was active reads "Connect & Unlock," a generic phrase often used in credential‑harvesting campaigns. Reputation data shows the domain appears on four independent blocklists—PhishDestroy, Polkadot, Enkrypt, and Codeesura—demonstrating consensus among threat‑intel providers that the site is malicious. VirusTotal analysis recorded 15 detections out of 95 scanned security vendors, reinforcing the phishing classification. The registrar information indicates the domain was registered through Netlify, a common platform for quickly deploying malicious fronts. No additional metadata such as creation date or registrar contact details were supplied.
Given the convergence of blocklist listings, multiple vendor detections, and the presence of a credential‑themed page title, defenders should treat this domain as a confirmed phishing source. Recommended actions include adding the domain and its resolved IP address to network blocklists, updating web‑filter rules to deny any HTTP/HTTPS traffic to the host, and monitoring Netlify‑associated subdomains for similar patterns. Continuous observation of the AS16509 range is advised, as attackers frequently leverage cloud services to rotate hosting locations.
网络安全情报
威胁响应 Pipeline
公共封禁名单状态
所用技术 · 2 identified
Netlify providers hosting and server-less backend services for web applications and static websites.
www.netlify.com 置信度 100%HTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org 置信度 100%VirusTotal 分析
存档证据
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。