verizon[.]tigvshw[.]cc
“Welcome to nginx!”
verizon.tigvshw.cc — 内容不可用 (HTTP 502). 证据摘要: VirusTotal 18/93 (ADMINUSLabs, Criminal IP, BitDefender, Cluster25, CRDF); Spamhaus DBL_PHISH; PhishDestroy score 95/100. 注册商: Gname.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
This domain, verizon.tigvshw.cc, is flagged as a brand impersonation threat designed to mimic Verizon’s official authentication portals. Analysis indicates the infrastructure was established to deceive users into submitting login credentials, likely for account takeover or fraudulent transactions. No drainer kit signatures were detected, suggesting a focused credential-harvesting campaign rather than broader financial theft. Infrastructure analysis reveals the following technical indicators: the domain was registered through Gname.com Pte. Ltd. on February 21, 2026, and resolves to IP address 172.67.146.2, hosted on Cloudflare’s network (AS13335). VirusTotal reports 18 out of 95 security vendors flagging the domain as malicious, while it appears on one additional blocklist. The domain lacks an SSL certificate, and its page title, 'Welcome to nginx!', suggests misconfigured or placeholder server settings. No Google Safe Browsing (GSB) detections were recorded at the time of assessment. The domain is currently offline, likely due to takedown actions or server misconfiguration. While the immediate threat is mitigated, residual risk remains for users who may have interacted with the site before its deactivation. Organizations should monitor for credential reuse attempts and consider proactive password resets for affected accounts. Users are advised to verify domain authenticity before entering credentials and to report suspicious login pages to their security teams.
威胁响应 Pipeline
公共封禁名单状态
VirusTotal 分析
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。