spotifypremiummod[.]com[.]in
“Suspected phishing site | Cloudflare”
ملاحظة محفوظة
تباين العناوين المرصود
ملخص الأدلة
Analysis of the domain spotifypremiummod.com.in indicates a phishing site impersonating Spotify, classified under generic phishing with an elevated risk level. The domain was created on March 11, 2026, and is currently offline as of the report date, July 24, 2026. Infrastructure analysis reveals the domain resolves to the IP address 104.21.27.215, hosted on Cloudflare's network (AS13335) in the United States. The nameservers are anderson.ns.cloudflare.com and venus.ns.cloudflare.com, consistent with Cloudflare's hosting infrastructure. The SSL certificate is issued by Google Trust Services (WE1), a common certificate authority for phishing domains leveraging Cloudflare services.
Detection data shows the domain is flagged by 9 of 94 security vendors on VirusTotal, a moderate but notable detection rate for a phishing site. It appears on three security blocklists and is blocked by PhishDestroy, MetaMask, and SEAL. AlienVault OTX records the domain in one threat intelligence pulse, indicating prior reporting in threat-sharing communities. The HTTP status returned is 403 (Forbidden), and the page title displayed is 'Suspected phishing site | Cloudflare,' suggesting Cloudflare's automated systems have identified and restricted access to the domain due to phishing concerns.
The registrar is National Informatics Centre, an Indian government entity, though this does not inherently indicate malicious intent by the registrar. No specific phishing kit or brand impersonation beyond the domain name itself is confirmed in the available data. Defenders should treat this domain as malicious, block it at the DNS and proxy levels, and monitor for related domains using the same registrar or hosting infrastructure. Further investigation into associated IPs or certificates may reveal additional linked phishing campaigns.
Data Coverage
استخبارات أمن الشبكات
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| OpenDNS | spotifypremiummod.com.in |
phishing | Phishing Block |
| Cloudflare DNS | spotifypremiummod.com.in |
malicious | Sinkholed |
| Hagezi Threat Feed | spotifypremiummod.com.in |
malicious | Sinkholed |
| DNS4EU | spotifypremiummod.com.in |
malicious | Sinkholed |
مسار الاستجابة للتهديدات Pipeline
تغطية قوائم الحظر
١٠ مصادر خارجية مراقبة · لقطة محفوظة 10/08/2026
المخطط الزمني للاكتشاف
-
Cloudflare Radar
تم حفظ فحص Cloudflare Radar · فتح الفحص
تحليل VirusTotal
تحليل إعدادات الموقع
هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب