Notification and current-status evidence
The sent-report ledger records the first outgoing report at .
The recorded recipient is abuse@cosmotown.com.
The latest stored availability evidence still shows the domain reachable; 5 months has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
inipin[.]top
“The United States Social Security Administration | SSA”
The domain inipin.top is a generic phishing site posing as a government entity, specifically impersonating the United States Social Security Administration (SSA). It is designed to deceive users into submitting personal information under the guise of official SSA communications. As of the latest verification, inipin.top has been suspended, but prior activity classified it as an elevated-risk phishing threat with no associated brand or drainer kit.
Technical indicators confirm the malicious nature of inipin.top. The domain is flagged by 17 of 95 security vendors on VirusTotal, including ADMINUSLabs, alphaMountain.ai, and BitDefender, though Google Safe Browsing has not yet flagged it. It appears on one security blocklist (PhishDestroy) and was registered through Cosmotown on March 11, 2026. The site resolves to IP address 192.142.54.88, hosted by Ultahost, Inc. in the Netherlands (AS214036), and uses an SSL certificate issued by Let's Encrypt (R12). Observed technologies include LiteSpeed and HTTP/3, with a page title mimicking the official SSA website. MX records point to inipin.top itself, and nameservers are ns1.hostcreed.com and ns2.hostcreed.com.
Users who may have interacted with inipin.top should immediately change any passwords entered on the site, particularly for government or financial accounts, and enable two-factor authentication (2FA) where available. Monitor accounts for unauthorized activity and report any suspected fraud to the Federal Trade Commission (FTC) at reportfraud.ftc.gov or the SSA Office of the Inspector General at oig.ssa.gov. To report the domain, submit it to Google Safe Browsing, PhishTank, or the registrar (Cosmotown) for further action.
Network Security Intelligence
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| YARAhub by abuse.ch | inipin.top/ |
malware | Detects file containing Telegram Bot API |
| YARAhub by abuse.ch | ultra.mediafire.com/2271;82l4gzhlv33gd-_w-npdn7xzeso7n8k5li2z43ey_bdstaqu2wjkimj14bt9wcosqu7zgvs13nyp_s4xy43xp7cno27ssxqkzyrxe8rxx3_698vqriiundu3goyncech0ugkh-juee-lb0fv39cyzf9j0i-4hempnveft02pjp2rkbfn0_6jksb4-fzkzeyxx4mklq/x3rwmx60uldn7km/ssa_e-file.vb |
malware | Detect files disabling or modifying Windows Defender, Windows Firewall, or Microsoft Smartscreen |
| Hagezi Threat Feed | inipin.top |
malicious | Sinkholed |
| DNS4EU | inipin.top |
malicious | Sinkholed |
| DigiCert UltraDNS | www.mediafire.com |
malicious | Sinkholed |
| DNS4EU | ultra.mediafire.com |
malicious | Sinkholed |
| DigiCert UltraDNS | ultra.mediafire.com |
malicious | Sinkholed |
Threat Response Pipeline
Public Blocklist Status
Stored Capture
Domain Intelligence
Technical detailsDNS, SSL SANs, timestamps
ICANN OVERSIGHT
Accreditation and RAA context
Accreditation and RAA context
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Technologies · 2 identified
High-performance web server compatible with Apache configurations.
Third major version of HTTP protocol, built on QUIC for faster, more reliable connections.
VirusTotal Analysis
Site Performance Analysis
Google PageSpeed Insights — mobile performance audit of inipin.top · checked Mar 11, 2026
Evidence & External Reports
PD-20260311-A5F7FE Recipient: abuse@cosmotown.com Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive