Notification and current-status evidence
The sent-report ledger records the first outgoing report at .
The recorded recipient is abuse@hoganhost.com.ng.
The latest stored availability evidence still shows the domain reachable; 4 months has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
proexchangeactivation[.]website
Phishing and security check for proexchangeactivation.website
“OFFICIAL EXCHANGEACTIVATION”
Analysis indicates that proexchangeactivation.website is actively hosting a counterfeit Exchange activation portal. The site returns HTTP 302 redirects and presents the page title “OFFICIAL EXCHANGEACTIVATION”. It is built on WordPress with MySQL and PHP back‑end, and includes client‑side libraries such as particles.js, Slick and Smartsupp, as well as embedded YouTube content. The server presents a Let’s Encrypt R12 certificate and is reachable at 79.137.33.241, an address assigned to OVH SAS in France (AS16276). DNS resolution uses nsb1.webhostingbliss.com and nsb2.webhostingbliss.com. The domain was registered on 13 March 2026 through NameSilo, LLC and remains active. Reputation metrics are poor: Gridinsoft assigns a score of 0/100, and the domain appears on one security blocklist. VirusTotal scans show 2 of 94 security vendors flag the domain, confirming malicious intent. PhishDestroy has already blocked the site. The observed evidence aligns with the “Fake Exchange” scam type, targeting users seeking Microsoft Exchange services. No further content analysis is available, so the exact phishing workflow and credential collection mechanisms remain uncertain. Defenders should block the domain and its IP at network perimeter, monitor DNS queries for the associated nameservers, and update endpoint detection rules to flag the Let’s Encrypt certificate fingerprint and the observed technology stack. Continuous re‑scanning of the URL is recommended to capture any evolving payloads.
Network Security Intelligence Registrar context
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Private YARA rules | www.youtube.com/s/player/74edf1a3/player_es6.vflset/en_us/base.js |
audit | Hunting_JS_WebAssembly |
| DNS4EU | proexchangeactivation.website |
malicious | Sinkholed |
Threat Response Pipeline
Public Blocklist Status
Stored Capture
Domain Intelligence
Technical detailsDNS, SSL SANs, timestamps
ICANN OVERSIGHT
Accreditation and RAA context
Accreditation and RAA context
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Technologies · 11 identified
Open-source CMS powering over 40% of websites worldwide.
Open-source relational database management system.
Server-side scripting language designed for web development.
High-performance web server compatible with Apache configurations.
Live chat and visitor recording tool for customer support.
Plugin to detect and restore deprecated jQuery features.
Fast, small JavaScript library simplifying HTML manipulation, event handling, and Ajax.
Third major version of HTTP protocol, built on QUIC for faster, more reliable connections.
VirusTotal Analysis
Site Performance Analysis
Google PageSpeed Insights — mobile performance audit of proexchangeactivation.website · checked Mar 13, 2026
Evidence & External Reports
PD-20260313-9246DE Recipient: abuse@hoganhost.com.ng Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive