Notification and current-status evidence
The sent-report ledger records the first outgoing report at .
The recorded recipient is abuse@ovh.net.
The latest stored availability evidence still shows the domain reachable; 7 months has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
osg138[.]org
Phishing- und Sicherheitsprüfung für osg138.org
“Osg138 : Dunia Game Inovatif yang Membawa Anda Berjelajah”
osg138.org — Letzter bekanntermaßen aktiv (HTTP 200). Markenidentität: Telegram; Betrugstyp: Brand Impersonation. Zusammenfassung der Beweislage: VirusTotal 3/91 (alphaMountain.ai, CRDF, Gridinsoft); PhishDestroy score 75/100. Registrar: NameCheap.
Die ausführliche Analyse von PhishDestroy AI bleibt auf Englisch, damit der ursprüngliche forensische Bericht unverändert bleibt.
Evidence Analysis
This domain, osg138.org, is flagged as a brand impersonation threat targeting Telegram, a widely used messaging platform. Analysis indicates the site was designed to deceive users into believing it was an official or affiliated Telegram service, likely for credential theft or unauthorized access to accounts. The page title, 'Osg138 : Dunia Game Inovatif yang Membawa Anda Berjelajah,' suggests an attempt to lure users with gaming-related content, a common tactic to mask malicious intent under seemingly legitimate themes. Infrastructure analysis reveals the domain was registered on December 30, 2023, through NameCheap, Inc. and resolves to the IP address 87.98.238.39. Security vendor assessments on VirusTotal show 3 out of 95 engines flagging the domain as malicious. The domain appears on one security blocklist and was previously blocked by PhishDestroy. Technologies detected include WordPress, MySQL, PHP, Apache HTTP Server, and AMP, with a Let's Encrypt SSL certificate providing HTTPS encryption, a tactic often used to appear legitimate. The domain is currently offline, reducing immediate risk to users. However, residual threats persist, including potential reuse of the infrastructure or re-registration under a similar name. Organizations and users are advised to monitor for related domains, implement blocklist updates, and verify the authenticity of any communication claiming affiliation with Telegram. Vigilance is recommended, particularly for users who may have interacted with the domain prior to its takedown.
Datenabdeckung12 recorded checks
Erkenntnisse zur Netzwerksicherheit
Pipeline zur Reaktion auf Sicherheitsbedrohungen
Status der öffentlichen Sperrliste
Gespeicherte Aufnahme
Domain-Intelligenz
Technische DetailsDNS, SSL-SANs, Zeitstempel
ICANN OVERSIGHT
Akkreditierung und RAA-Kontext
Akkreditierung und RAA-Kontext
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Technologien · 5 identified
Open-source CMS powering over 40% of websites worldwide.
Open-source relational database management system.
Server-side scripting language designed for web development.
Most widely used open-source HTTP server software.
VirusTotal-Analyse
Archivierte Beweise
Website-Performanceanalyse
Google PageSpeed Insights — mobile performance audit of osg138.org · checked Jun 27, 2026
Nachweise und externe BerichteIndependent lookups and source reports
PD-20260104-6A7AF1 Recipient: abuse@ovh.net Victim safety and official reportingImmediate actions and verified reporting channels
Wenn Sie Kontoanmeldeinformationen, persönliche oder Zahlungsinformationen eingegeben oder eine Datei von dieser Domain heruntergeladen haben, ergreifen Sie sofort Maßnahmen. Nachfolgend finden Sie Ressourcen, die Ihnen helfen, den Vorfall zu melden und sich zu schützen.
Melden Sie sich bei Ihren örtlichen Behörden
Wählen Sie Ihr Land aus, um Offizielle Kontakte im Bereich Cyberkriminalität oder einen Beschwerdeentwurf erstellen → zu erhalten.