fjsoi.com
“XAUT”
Evidence Summary
Analysis of the domain fjsoi.com indicates it is associated with generic phishing infrastructure. The domain was registered on March 20, 2026, through GMO Internet, Inc., and remains active as of the report date. It is currently flagged on one security blocklist, PhishDestroy, though no additional detection details are available from other vendors at this time. Infrastructure analysis reveals the domain resolves to the IP address 104.21.28.62, which is hosted on Cloudflare’s network, as evidenced by the nameservers johnathan.ns.cloudflare.com and serenity.ns.cloudflare.com.
While VirusTotal scans from 91 vendors returned no detections, this absence does not confirm the domain’s safety or malicious intent, as phishing domains often evade initial detection during early deployment phases. The domain’s content and specific phishing target remain unconfirmed, as no brand, page title, or scam classification details were provided in the available intelligence. Defenders should treat this domain as potentially malicious based on its presence on a security blocklist and its recent registration timeline.
Monitoring for additional detections, changes in resolution, or shifts in hosting infrastructure is recommended. If observed in network traffic, the domain should be blocked or investigated further, particularly in environments where phishing threats pose a high risk. No evidence suggests this domain is linked to a known phishing kit or campaign at this stage.
Detection timeline
-
Domain status
Reachable → Unreachable
-
First recorded
First stored value: Reachable
Threat Response Pipeline
Public Blocklist Status
Submitted Evidence Snapshot
- Sent
- Ledger records
- 1
- Case ID
PD-20260727-856531
Blocklist coverage
11 monitored external feeds · stored snapshot Sep 10, 2026
Stored Capture
Domain Intelligence
Technical detailsDNS, SSL SANs, timestamps
ICANN OVERSIGHT
Accreditation and RAA context
Accreditation and RAA context
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Technologies · 5 identified
Ant Design is a UI library that can be used with data flow solutions and application frameworks in any React ecosystem.
ant.design 100% confidenceVue.js is an open-source model–view–viewmodel JavaScript framework for building user interfaces and single-page applications.
vuejs.org 100% confidenceCloudflare Browser Insights is a tool that measures the performance of websites from the perspective of users.
www.cloudflare.com 100% confidenceCloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com 100% confidenceHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100% confidenceVirusTotal Analysis
Archived Evidence
Site Performance Analysis
Google PageSpeed Insights — mobile performance audit of fjsoi.com · checked Jul 27, 2026
Technologies
5 high-confidence technologies identified
Community intelligence
1 community report
CategoryPIGBUTCHERING
Evidence & External Reports
“Narrative On February 27, 2026, the victim was contacted through LinkedIn by an individual identifying himself as "Harold Mao." Shortly after the initial contact, he asked her to continue communicating through WhatsApp, where they remained in frequent contact over the following several months. During this time, "Harold Mao" gained the victim’s trust through ongoing personal communications and encouraged her to rely on his financial advice. He introduced what he represented as a cryptocurrency”
PD-20260727-856531 Recipient: abuse@internet.gmo Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive