Notification and current-status evidence
The sent-report ledger records the first outgoing report at .
The recorded recipient is abuse@alibaba-inc.com.
The latest stored availability evidence still shows the domain reachable; 7 months has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
imba97[.]cn
Análisis de phishing y seguridad de imba97.cn
“怠惰のコエ - imba久期 BLOG”
imba97.cn — Último activo conocido (HTTP 200). Suplantación de marca: Chatgpt; Tipo de estafa: Brand Impersonation. Resumen de las pruebas: VirusTotal 5/91 (ADMINUSLabs, alphaMountain.ai, CRDF, Fortinet, Gridinsoft); 1 external blocklist match (CryptoFirewall); PhishDestroy score 80/100. Registrador: 阿里云计算有限公司(万网).
El análisis detallado de PhishDestroy AI se mantiene en inglés para conservar el registro forense original.
The domain imba97.cn is a confirmed phishing site engaged in brand impersonation targeting ChatGPT users. It presents itself as an official ChatGPT portal to deceive visitors into entering credentials or sensitive information, constituting a credential-harvesting scam. No crypto drainer kit was detected on this domain. As of the latest verification, imba97.cn has been taken offline.
Technical analysis shows imba97.cn was flagged by 2 of 95 VirusTotal security vendors, including Fortinet and SOCRadar. The domain is registered through 阿里云计算有限公司(万网) with a creation date of 2016-01-18 00:34:57 and resolves to the IP address 172.67.140.106, hosted on Cloudflare’s network in the US. It appears on 2 security blocklists (PhishDestroy and CryptoFirewall) and uses an SSL certificate issued by Let’s Encrypt (R12). The observed page title was '怠惰のコエ - imba久期 BLOG', and detected technologies include Hexo, Node.js, and Cloudflare services. MX records point to mxdomain.qq.com, and nameservers are dns10.hichina.com and dns9.hichina.com.
Individuals who interacted with imba97.cn should immediately change any passwords entered on the site, especially for ChatGPT or linked accounts. Enable two-factor authentication (2FA) on all critical services to prevent unauthorized access. Monitor accounts for suspicious activity, such as unauthorized logins or transactions. Report the phishing domain to Google Safe Browsing, the impersonated brand’s security team (OpenAI for ChatGPT), and local cybercrime authorities. If financial or crypto accounts were exposed, contact the respective platforms to secure funds and review transaction histories for fraud.
Proceso de respuesta ante amenazas Pipeline
Estado de la lista de bloqueados pública
Tecnologías · 8 identified
JavaScript runtime built on Chrome V8 engine for server-side development.
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
Performance monitoring tool that measures website speed from real users.
www.cloudflare.comWeb infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
Análisis de VirusTotal
Evidencias archivadas
Análisis del rendimiento del sitio
Google PageSpeed Insights — mobile performance audit of imba97.cn · checked Mar 2, 2026
Datos y informes externos
PD-20260105-B3497B Recipient: abuse@alibaba-inc.com ¿Te ha afectado esta página web?
Si ingresó credenciales de cuenta, información personal o de pago, o descargó un archivo de este dominio, tome medidas inmediatas. A continuación encontrará recursos que le ayudarán a informar el incidente y protegerse.
Informa a las autoridades locales
Seleccione su país para obtener contactos oficiales de cibercrimen o crear un borrador de queja →.
Comprobar cualquier dominio
Análisis de amenazas utilizando listas de bloqueo almacenadas, WHOIS, DNS y evidencia de escaneo público
Escanear ahoraDenunciar un intento de phishing
Envía los dominios sospechosos a nuestra base de datos de amenazas: protege a la comunidad
DenunciarFlujo de amenazas en tiempo real
Informes de phishing recientes y cambios de disponibilidad observados
MonitorizarMantente informado, mantente a salvo
Supervisa las amenazas en tiempo real o impugna esta entrada si crees que se trata de un falso positivo.