web-sys.digital
“web-sys.digital”
The domain web-sys.digital is currently down, indicating it has been taken down. It was used in a generic phishing operation.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
证据摘要
The domain web-sys.digital is a confirmed generic phishing site posing an elevated risk of credential theft or fraudulent activity. It does not impersonate a specific brand or deploy a known crypto drainer kit. As of the latest verification, web-sys.digital has been taken offline, though prior activity indicates it was actively used for phishing attempts.
Technical indicators confirm the domain's malicious nature: 11 of 95 VirusTotal security vendors flagged web-sys.digital, including ADMINUSLabs, alphaMountain.ai, and BitDefender. The domain was registered through Web Commerce Communications Limited on November 10, 2025, and resolves to the IP address 77.110.112.57, hosted in Russia under AS207713 GLOBAL INTERNET SOLUTIONS LLC. It appears on one security blocklist (PhishDestroy) and uses an SSL certificate issued by Internet Widgits Pty Ltd. The observed page title was identical to the domain name, and Gridinsoft assigned it a trust score of 0/100.
Individuals who interacted with web-sys.digital should immediately change any credentials entered on the site, enable two-factor authentication (2FA) on affected accounts, and monitor for unauthorized transactions or identity fraud. Victims are advised to report the domain to their email provider, browser security teams, and relevant cybersecurity organizations such as the Anti-Phishing Working Group (APWG) or local cybercrime units. If financial data was exposed, contact the associated institution to secure accounts and review recent activity for signs of compromise.
网络安全情报
Forensic History & Detection Timeline
-
Domain Status Transition Aug 1, 2026 · 00:55 UTCDomain state transitioned from dead to alive.
-
Cloudflare Radar Scan Mar 7, 2026 · 13:58 UTCCloudflare Radar scan registered: View Radar report.
-
Domain Status Transition Mar 1, 2026 · 05:06 UTCDomain state transitioned from alive to dead.
威胁响应 Pipeline
公共封禁名单状态
探测与规避分析
隐身和流量分配检查
未观察到
在存储的扫描图像中未观察到遮蔽现象
针对该主机的爬虫与浏览器观察记录,以及针对“Keitaro”式流量分配系统的实时指纹检测。
- 存储的隐身标志
- 未观察到
- 伪装评分
- 0/6
- 上次隐形扫描
扫描说明: dns_error: raw=dns_error; via=local_dns_prefilter
已保存的截图 · 2 sources
域名情报
技术详情DNS、SSL SAN、时间戳
ICANN OVERSIGHT
认证和 RAA 背景
认证和 RAA 背景
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
VirusTotal 分析
存档证据
社区报告
由 1 名社区成员报告;首次发现于 2025年11月19日
- 已存储报告
- 1
- 已报告的唯一 URL
- 1
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。