Notification and current-status evidence
The sent-report ledger records the first outgoing report at . A report was sent to the recorded registrar; contact details remain in Domain Intelligence. The latest stored availability evidence still shows the domain reachable; 8 days has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
gova[.]lat
“कर दंड सूचना - भारत सरकार”
Resumen de las pruebas
The domain gova.lat is currently classified as a generic phishing site with an elevated risk rating and an active status as of the report date, August 02, 2026. Intelligence sources indicate that the domain has been blocked by the PhishDestroy mitigation service and is listed on a single external security blocklist. VirusTotal analysis shows that nine out of ninety-one security vendors have flagged the domain as malicious, providing an early indication of malicious intent despite the relatively low detection ratio. No additional contextual data such as registrar information, hosting IP addresses, ASN, or SSL certificate details have been disclosed, limiting the depth of infrastructure profiling at this time.
Consequently, the precise hosting environment and potential command‑and‑control infrastructure remain unknown. The lack of publicly available page metadata, including page title or brand targeting, further constrains the ability to attribute the phishing campaign to a specific commodity or victim demographic. Defenders are advised to incorporate gova.lat into network‑level deny lists and update endpoint protection signatures to reflect the nine vendor detections.
Continuous monitoring of threat intelligence feeds for any emergence of additional indicators—such as IP resolution, registrar changes, or expanded blocklist listings—should be performed. Organizations employing web filtering should ensure that the domain is explicitly blocked, and security operations teams should consider correlating any internal DNS queries or HTTP requests to gova.lat with user activity logs to identify potential compromise attempts. Given the elevated risk level and active designation, proactive containment and rapid response measures are recommended to mitigate exposure to this phishing infrastructure.
Instantánea de evidencia enviada
- Enviado
- Registros del libro
- 1
- ID del caso
PD-20260802-251FE6- Artefacto PDF
- Evidencia en PDF
Fundamento jurídico
Texto completo de la evidencia
Policy Violations: Acceptable Use forbids illegal content; Spam & Abuse Policy prohibits phishing, fraud, malware; Dynadot may disable DNS and suspend domains
Applicable Laws: CFAA 18 U.S.C. §1030, Wire Fraud 18 U.S.C. §1343, CAN-SPAM Act
Data Coverage
Inteligencia de seguridad de red
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DNS4EU | gova.lat |
malicious | Sinkholed |
Proceso de respuesta ante amenazas Pipeline
Cobertura de listas de bloqueo
10 fuentes externas supervisadas · instantánea del 11/08/2026
10 fuentes externas supervisadas Sin coincidencias
Cronología de detección
-
Primer registro
Primer valor almacenado: Accesible
-
Estado del dominio
Accesible → Inaccesible
-
Estado del dominio
Inaccesible → Accesible
Captura guardada
Inteligencia de dominios
Detalles técnicosDNS, nombres TLS y marcas de tiempo
ICANN OVERSIGHT
Acreditación y contexto RAA
Acreditación y contexto RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Análisis de VirusTotal
¿Te ha afectado esta página web?
Si ingresó credenciales de cuenta, información personal o de pago, o descargó un archivo de este dominio, tome medidas inmediatas. A continuación encontrará recursos que le ayudarán a informar el incidente y protegerse.
Informa a las autoridades locales
Seleccione su país para obtener contactos oficiales de cibercrimen o crear un borrador de queja →.
Comprobar cualquier dominio
Análisis de amenazas utilizando listas de bloqueo almacenadas, WHOIS, DNS y evidencia de escaneo público
Escanear ahoraDenunciar un intento de phishing
Envía los dominios sospechosos a nuestra base de datos de amenazas: protege a la comunidad
DenunciarFlujo de amenazas en tiempo real
Informes de phishing recientes y cambios de disponibilidad observados
MonitorizarMantente informado, mantente a salvo
Supervisa las amenazas en tiempo real o impugna esta entrada si crees que se trata de un falso positivo.