whiskymuseum[.]at
“Whiskey - Angebote günstig in Aktion kaufen”
whiskymuseum.at — 隐形 · 可达. 诈骗类型:Generic Phishing. 证据摘要: VirusTotal 10/91 (ADMINUSLabs, alphaMountain.ai, Chong Lua Dao, ESET, Forcepoint ThreatSeeker); URLQuery 1 alert; 1 external blocklist match (CryptoFirewall); cloaking observed; PhishDestroy score 100/100.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
This domain, whiskymuseum.at, is flagged as a generic phishing site targeting consumers seeking discounted whiskey products. Analysis indicates the site mimics legitimate retail promotions, likely to harvest payment card details or distribute malware under the guise of limited-time offers. No specific brand impersonation is confirmed, but the page title 'Whiskey - Angebote günstig in Aktion kaufen' suggests a broad targeting of German-speaking users with fraudulent e-commerce tactics. The absence of a known drainer kit signature does not preclude the use of custom or obfuscated skimming scripts. Infrastructure analysis reveals multiple high-confidence technical indicators. The domain resolves to IP 78.46.146.14, hosted on AS24940 (Hetzner Online GmbH) in Germany, a common provider for both legitimate and malicious operations. VirusTotal detection shows 12 of 95 security vendors flagging the domain, with a creation date of February 21, 2026, indicating a likely typo-squatted or lookalike registration. The domain appears on two security blocklists, including PhishDestroy and CryptoFirewall, and employs a Let's Encrypt SSL certificate (serial E7) to feign legitimacy. No Google Safe Browsing (GSB) listing is noted, though this may reflect a lag in propagation. Current status shows the domain as offline, likely due to takedown actions or voluntary suspension by the hosting provider. While the immediate threat is mitigated, residual risk persists for users who may have interacted with the site prior to deactivation. Historical DNS records or cached pages could still expose victims to follow-up attacks, such as credential stuffing or secondary phishing campaigns. Users are advised to verify transaction histories, revoke compromised payment details, and monitor for unauthorized activity. Organizations should update blocklists to include the domain and IP, while security teams may investigate related infrastructure for coordinated threats.
网络安全情报
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DNS4EU | whiskymuseum.at |
malicious | Sinkholed |
威胁响应 Pipeline
公共封禁名单状态
所用技术 · 6 identified
WordPress is a free and open-source content management system written in PHP and paired with a MySQL or MariaDB database. Features include a plugin architecture and a template system.
wordpress.org 置信度 100%Query Migrate is a javascript library that allows you to preserve the compatibility of your jQuery code developed for versions of jQuery older than 1.9.
github.com 置信度 100%jQuery is a JavaScript library which is a free, open-source software designed to simplify HTML DOM tree traversal and manipulation, as well as event handling, CSS animation, and Ajax.
jquery.com 置信度 100%VirusTotal 分析
存档证据
网站性能分析
Google PageSpeed Insights — mobile performance audit of whiskymuseum.at · checked Mar 2, 2026
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。