www-spendesk[.]co[.]com
“Spendesk | Spendesk login | All-in-One Spend Management Platform | Join Spendesk”
www-spendesk.co.com — 未验证. 品牌冒充:["curve"]; 诈骗类型:Credential Phishing. 证据摘要: VirusTotal 12/91 (ADMINUSLabs, alphaMountain.ai, BitDefender, Chong Lua Dao, CyRadar); Spamhaus DBL_PHISH; 3 external blocklist matches (Polkadot, Enkrypt, Codeesura); PhishDestroy score 86/100. 注册商: Moniker Online Services.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
Analysis of the domain www-spendesk.co.com indicates a high-risk credential phishing operation targeting users of the Spendesk financial management platform. The domain, created on August 16, 1997, is registered through Moniker Online Services LLC and currently resolves to IP address 104.21.76.26, hosted under AS13335 (Cloudflare, Inc.) in the United States. Infrastructure analysis reveals the absence of an SSL certificate, a critical security gap for a site purporting to handle login credentials. The page title, 'Spendesk | Spendesk login | All-in-One Spend Management Platform | Join Spendesk,' explicitly mimics the branding and login flow of the legitimate Spendesk platform, aligning with the credential phishing classification.
Security vendor detections are notable: 11 of 95 engines on VirusTotal flagged the domain as malicious. The domain appears on four security blocklists, including PhishDestroy, Polkadot, Enkrypt, and Codeesura, further corroborating its malicious classification. Nameservers are configured as ns1.nic.co.com, ns2.nic.co.com, ns3.nic.co.com, and ns4.nic.co.com, a pattern consistent with domains leveraging the .co.com namespace for phishing campaigns. At the time of this report, the domain has been taken offline, though historical resolution and detection data remain actionable for defenders.
Defenders are advised to block the domain and its associated IP (104.21.76.26) at the network level, update endpoint protection signatures, and monitor for credential reuse attempts from users who may have interacted with the site prior to its takedown. The registration age (nearly three decades) does not confer legitimacy, as the domain was likely repurposed for malicious activity. No evidence of a phishing kit or additional infrastructure (e.g., redirects, C2 servers) is present in the available data, but the alignment of the page title with a financial platform login portal is sufficient to classify this as a targeted credential harvesting attempt.
威胁响应 Pipeline
公共封禁名单状态
VirusTotal 分析
存档证据
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。