fomchoby[.]digital
“Helvionex”
fomchoby.digital — Contenido no disponible. Suplantación de marca: Argent; Tipo de estafa: Brand Impersonation. Resumen de las pruebas: VirusTotal 15/91 (ADMINUSLabs, BitDefender, CRDF, Chong Lua Dao, CyRadar); Google Safe Browsing flagged; PhishDestroy score 95/100. Registrador: PDR.
El análisis detallado de PhishDestroy AI se mantiene en inglés para conservar el registro forense original.
Analysis as of July 24, 2026 indicates that the domain fomchoby.digital has been taken offline but exhibits multiple indicators of a high‑risk brand‑impersonation campaign targeting the financial services brand argent. The domain was registered on February 21, 2026 through PDR Ltd. d/b/a PublicDomainRegistry.com and resolves to the Cloudflare‑owned address 104.21.45.20, which belongs to ASN 13335 (Cloudflare, Inc.) and is located in the United States. The hosting infrastructure uses Cloudflare services and supports HTTP/3, with authoritative nameservers dax.ns.cloudflare.com and kira.ns.cloudflare.com. The site presented the page title “Helvionex”, which does not correspond to the advertised brand, and the SSL certificate was issued by Google Trust Services under the WE1 designation, confirming the use of a legitimate certificate authority but not validating the legitimacy of the content. Reputation data shows a Gridinsoft trust score of 0 out of 100, indicating extreme distrust.
Google Safe Browsing classifies the domain as a social‑engineering threat, and three independent blocklists (PhishDestroy, MetaMask, and SEAL) have already listed the host. AlienVault OTX reports the domain in a single threat‑intelligence pulse. VirusTotal analysis flagged the domain by 21 of 95 security vendors, reinforcing the malicious assessment. The overall risk rating is high, and the current status is offline, suggesting that the operators may be rotating infrastructure.
While the technical footprint is well documented, the exact content served before takedown has not been publicly released, and the specific lure mechanisms remain unknown. Defenders should continue to block the domain at network perimeters, update URL filtering rules with the observed indicators, and monitor the associated IP address 104.21.45.20 for any re‑use in future campaigns. Ongoing surveillance of the Cloudflare ASN and related nameservers is recommended, as the infrastructure can be repurposed quickly.
Proceso de respuesta ante amenazas Pipeline
Estado de la lista de bloqueados pública
Captura guardada
Inteligencia de dominios
Detalles técnicosDNS, SAN de SSL, marcas de tiempo
ICANN OVERSIGHT
Acreditación y contexto RAA
Acreditación y contexto RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Tecnologías · 2 identified
Cloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com 100 % de confianzaHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100 % de confianzaAnálisis de VirusTotal
Evidencias archivadas
Datos y informes externos
¿Te ha afectado esta página web?
Si ingresó credenciales de cuenta, información personal o de pago, o descargó un archivo de este dominio, tome medidas inmediatas. A continuación encontrará recursos que le ayudarán a informar el incidente y protegerse.
Informa a las autoridades locales
Seleccione su país para obtener contactos oficiales de cibercrimen o crear un borrador de queja →.
Comprobar cualquier dominio
Análisis de amenazas utilizando listas de bloqueo almacenadas, WHOIS, DNS y evidencia de escaneo público
Escanear ahoraDenunciar un intento de phishing
Envía los dominios sospechosos a nuestra base de datos de amenazas: protege a la comunidad
DenunciarFlujo de amenazas en tiempo real
Informes de phishing recientes y cambios de disponibilidad observados
MonitorizarMantente informado, mantente a salvo
Supervisa las amenazas en tiempo real o impugna esta entrada si crees que se trata de un falso positivo.