MALICIOUS — CRITICAL
wordpress-207173-0.cloudclusters.net 网络钓鱼与安全检查
wordpress-207173-0[.]
Analysis of the domain wordpress-207173-0.cloudclusters.net indicates it was actively involved in a brand impersonation campaign targeting Facebook.
- VirusTotal
- 7/95
- Blocklists
- No stored match
- 可用性
- 内容不可用 · HTTP 502
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
wordpress-207173-0.cloudclusters.net — 内容不可用 (HTTP 502). 品牌冒充:Facebook; 诈骗类型:Brand Impersonation. 证据摘要: VirusTotal 7/95 (alphaMountain.ai, CRDF, CyRadar, Fortinet, Gridinsoft); PhishDestroy score 71/100. 注册商: NetEarth One.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
Evidence Analysis
Analysis of the domain wordpress-207173-0.cloudclusters.net indicates it was actively involved in a brand impersonation campaign targeting Facebook. The domain, registered on February 21, 2026, through registrar NetEarth One, Inc., resolved to the IP address 108.181.157.241, hosted on AS40676 (Psychz Networks) in the United States. At the time of assessment, the domain was offline, though it had been flagged by at least one security blocklist and detected by 7 of 95 security vendors on VirusTotal, suggesting prior malicious activity.
The absence of an SSL certificate and the use of CloudClusters nameservers (ns1.cloudclusters.net, ns2.cloudclusters.net) align with patterns observed in low-effort phishing infrastructure. The page title, 'wordpress – Just another WordPress site,' does not provide definitive evidence of the exact content served, but the scam type is explicitly classified as brand impersonation in available threat intelligence. Defenders should treat this domain as compromised infrastructure and prioritize blocking both the domain and its resolving IP within network security controls.
Given the domain's current offline status, further forensic analysis may be limited, but historical DNS and WHOIS records should be preserved for potential incident response. The Gridinsoft trust score of 0/100 reinforces the assessment of elevated risk, though the lack of additional context (e.g., phishing kit signatures, payload samples) prevents a more granular classification.
Stored source results
Recorded verdicts and infrastructure observations for this domain.
数据覆盖范围12 recorded checks
威胁响应 Pipeline
公共封禁名单状态
已保存的截图
域名情报
技术细节DNS、SSL SAN、时间戳
ICANN OVERSIGHT
Registration: cloudclusters.net
认证和 RAA 背景
认证和 RAA 背景
Registrar accreditation and DNS abuse obligations
For the registrable domain cloudclusters.net behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
VirusTotal 分析
证据与外部报告Independent lookups and source reports
PD-20260120-77A829 Recipient: a-b-u-s-e.whois.field@netearthone.com Victim safety and official reportingImmediate actions and verified reporting channels
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。