Phishing detection: comecome.click
Alibaba Investigate
Domain
comecome.click1 CT host on apex
IP
185.221.216.117
URL
https://comecome.click/zxm/xx/alibaba/index.html
Cert
YR2
Phishunt analysis Beta
45
high suspicion likely_phishingheuristic risk score · not a probability
Why?
- +6.1 Google Safe Browsing
- +5.3 Keyword match
- +4.5 Brand in title
- +4.1 Brand in screenshot
- +3.9 Password field
- +3.0 OpenPhish
- +2.4 ASN reputation
- +2.2 Country mismatch
- +1.7 Shared IP cluster
- +1.3 Suspicious TLD
- +1.1 No CSP header
- +1.1 No HSTS header
- +1.0 Site cluster
- +0.8 Young domain
- +0.6 Brand impersonation in path
- +0.6 Login text in screenshot
- +0.5 Young certificate
- +0.3 Free CA
- +0.3 Long domain
- +0.1 External scripts
- Boosted to 45: Google-flagged credential form
22 signals fired · detector v3.0.0
AI analysis AIBeta
Credential harvesting
Impersonates Alibaba by embedding the brand in the URL path of an unrelated domain. Contains a password input and is flagged by Google Safe Browsing as social engineering. Hosted in the UK via Host4Geeks and confirmed by OpenPhish.
Google Safe BrowsingPassword fieldBrand impersonation in path
AI-generated from stored detector signals - the AI never visited the site. · 2026-09-04 · confidence 87%
Domain & Network
Whois
Registrar
Sav.com, LLC
Network
Country
United Kingdom
Hosting
Host4Geeks LLC
ASN
AS393960
TLS Cert
YR2
GSB category: SOCIAL_ENGINEERING
CleanPhishTank · TweetFeed · urlscan.io
Requests
Resources
Observables
Related websites
Report this phishing
Submit to blocklists
urlscan
VirusTotal
Whois
ipinfo
Greynoise