Notification and current-status evidence
The sent-report ledger records the first outgoing report at . A report was sent to the recorded registrar; contact details remain in Domain Intelligence. The latest stored availability evidence still shows the domain reachable; 4 months has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
mysaiban[.]com
“साईबन निसर्गाचा कुशीत वसलेले एक टुमदार घरटं...”
Observación almacenada
Contraste de títulos observado
mysaiban.com was observed on 2026-07-12 as an active brand‑impersonation site targeting Google. The domain was registered on 2017-06-22 through PDR Ltd. d/b/a PublicDomainRegistry.com and resolves to 103.117.212.145, an address owned by AS140641 YOTTA NETWORK SERVICES PRIVATE LIMITED in India. The site returns HTTP 200 and presents a page titled “साईबन निसर्गाचा कुशीत वसलेले एक टुमदार घरटं…”, which does not reference the impersonated brand but is used as a lure in email‑based scams. The infrastructure is hosted behind a LiteSpeed web server and employs a free TLS certificate, indicating a valid TLS handshake but offering no authentication of the operator.
Static analysis shows the page loads YouTube embeds, Bootstrap, Slick, OWL Carousel, jQuery, Google Hosted Libraries and Google Analytics, suggesting a typical content‑driven template rather than a custom phishing kit. The domain received a Gridinsoft trust score of 0/100 and appears on one external blocklist. VirusTotal scanned the host and 11 of 95 security vendors flagged it as malicious, reinforcing the suspicion. Nameservers are ns301.ownmyserver.com, ns302.ownmyserver.com, ns311.ownmyserver.com and ns312.ownmyser, all pointing to the same hosting provider.
Analysis confirms the site is being used to impersonate Google in email campaigns, likely to harvest credentials or deliver malware. While the exact payload delivered to victims remains unknown, the presence of analytics and video elements suggests the operator tracks visitor interaction. Defenders should block the domain and its associated IP at perimeter firewalls, update email filtering rules to flag messages containing links to mysaiban.com, and consider sinkholing the host to disrupt traffic. Continuous monitoring of the listed nameservers and the ASN is recommended, as the operator may shift to adjacent IP ranges or replicate the site under new domains.
Registro de reporte enviado
Instantánea de evidencia enviada
- Enviado
- Registros del libro
- 1
- ID del caso
PD-20260318-2784A8- Título de la página capturada
- साईबन निसर्गाचा कुशीत वसलेले एक टुमदार घरटं...
- Artefacto PDF
- Evidencia en PDF
Fundamento jurídico
Texto completo de la evidencia
Acceptable Use Policy: The domain mysaiban.com is engaged in phishing activities, which constitutes a clear violation of your AUP prohibiting fraud and deception.
Terms of Service: The ongoing use of this domain for illegal activities breaches your TOS, which reserves the right to suspend or terminate services for such violations.
Applicable Laws (IN):
Information Technology Act, 2000 (Section 66): This section addresses computer-related offenses, including hacking and phishing, making such activities punishable under Indian law.
Indian Penal Code (Section 420): This section pertains to cheating and dishonestly inducing delivery of property, applicable to phishing schemes that deceive individuals into providing sensitive information.
Regulatory Note: Failure to take prompt action against this domain may result in liability under applicable laws and could expose your organization to regulatory scrutiny. Immediate suspension is advised to mitigate potential risks.
Inteligencia de seguridad de red
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Private YARA rules | www.youtube.com/s/player/21cd2156/player_es6.vflset/en_us/base.js |
audit | Hunting_JS_WebAssembly |
| DNS4EU | mysaiban.com |
malicious | Sinkholed |
Proceso de respuesta ante amenazas Pipeline
Cobertura de listas de bloqueo
10 fuentes · sincronizado el 10/08/2026
Cronología de detección
Observaciones almacenadas en orden cronológico.
-
VirusTotal
VirusTotal: 0 → 9
Captura guardada
Inteligencia de dominios
Detalles técnicosDNS, nombres TLS y marcas de tiempo
ICANN OVERSIGHT
Acreditación y contexto RAA
Acreditación y contexto RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Análisis de VirusTotal
Análisis del rendimiento del sitio
Google PageSpeed Insights — mobile performance audit of mysaiban.com · checked Mar 18, 2026
¿Te ha afectado esta página web?
Si ingresó credenciales de cuenta, información personal o de pago, o descargó un archivo de este dominio, tome medidas inmediatas. A continuación encontrará recursos que le ayudarán a informar el incidente y protegerse.
Informa a las autoridades locales
Seleccione su país para obtener contactos oficiales de cibercrimen o crear un borrador de queja →.
Comprobar cualquier dominio
Análisis de amenazas utilizando listas de bloqueo almacenadas, WHOIS, DNS y evidencia de escaneo público
Escanear ahoraDenunciar un intento de phishing
Envía los dominios sospechosos a nuestra base de datos de amenazas: protege a la comunidad
DenunciarFlujo de amenazas en tiempo real
Informes de phishing recientes y cambios de disponibilidad observados
MonitorizarMantente informado, mantente a salvo
Supervisa las amenazas en tiempo real o impugna esta entrada si crees que se trata de un falso positivo.