wordpress[.]musiclol[.]me
“shopify”
wordpress.musiclol.me — 未验证. 品牌冒充:Facebook; 诈骗类型:Social Media Phishing. 证据摘要: VirusTotal 19/95 (ADMINUSLabs, Criminal IP, alphaMountain.ai, BitDefender, CRDF); CF Radar malicious; PhishDestroy score 95/100. 注册商: GANDI SAS.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
The domain wordpress.musiclol.me is identified as a brand impersonation threat, specifically targeting Facebook. The risk level is elevated, and the domain has been taken offline. The page title 'shopify' does not align with the brand being impersonated, suggesting potential multi-faceted attack vectors or a misconfiguration.
Infrastructure analysis reveals that the domain resolves to the IP address 52.45.225.66, which is located in the United States and is part of the AS14618 network operated by Amazon.com, Inc. The domain was created on June 28, 2025, and is registered through GANDI SAS. The SSL certificate is issued by Amazon RSA 2048 M02. According to VirusTotal, 19 out of 95 security vendors flag this domain as malicious. The domain appears on two security blocklists: PhishDestroy and PhishingDB. Google Safe Browsing (GSB) has also marked it as a phishing site.
The domain is currently offline, which reduces the immediate risk to potential victims. However, the historical data and blocklist entries indicate that the domain was actively used in phishing campaigns. While the site is not currently accessible, users should remain cautious of any subsequent attempts to re-register or reactivate the domain. Security teams are advised to monitor the domain for any signs of reactivation and to implement additional protective measures to prevent exposure to similar threats. Users who have interacted with the domain should monitor their accounts for any unauthorized activity and consider changing their passwords.
网络安全情报
威胁响应 Pipeline
公共封禁名单状态
VirusTotal 分析
存档证据
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。