zfjqcl[.]top
zfjqcl.top — 内容不可用 (HTTP 502). 证据摘要: VirusTotal 2/93 (alphaMountain.ai); 2 external blocklist matches (ScamSniffer, Enkrypt); PhishDestroy score 66/100.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
Analysis indicates that the domain zfjqcl.top was registered on February 21 2026 and subsequently observed by multiple threat intelligence sources. The domain resolves to the IPv4 address 208.91.196.46, which belongs to the AS40034 network operated by Confluence Networks Inc. and is geolocated in the United States. The hosting IP appears on three independent blocklists—PhishDestroy, ScamSniffer, and Enkrypt—confirming that it is associated with malicious activity. The site employed an SSL certificate identified as R10, but no additional certificate details are publicly disclosed.
VirusTotal scans show that two out of ninety‑three security vendors flagged the domain as malicious, reinforcing the blocklist observations. The domain’s current operational status is reported as offline, suggesting that the phishing infrastructure has been taken down or is no longer serving content. No publicly available page title, brand target, or detailed payload information has been released, leaving the exact phishing vector unverified.
Defenders should continue to block the domain and its associated IP address at network perimeter devices, ensure that the three blocklists are incorporated into existing URL filtering solutions, and monitor for any re‑appearance of the IP or similar registrant patterns. Ongoing reconnaissance of the registrar and DNS records is advised to detect potential repurposing of the domain or related infrastructure. The limited detection footprint—three blocklists and two vendor flags—indicates a low‑volume campaign, but the elevated risk rating warrants proactive mitigation.
威胁响应 Pipeline
公共封禁名单状态
取证情报
VirusTotal 分析
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。