MALICIOUS — CRITICAL
formexora[.]com
6 of 91 security engines flagged the domain; URLQuery recorded 1 threat-system alert; the latest stored check returned HTTP 200.
- VirusTotal
- 6/91
- Blocklists
- No stored match
- Disponibilité
- Dernier actif connu · HTTP 200
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Notification and current-status evidence
The sent-report ledger records the first outgoing report at .
The recorded recipient is abuse@first-colo.net.
The latest stored availability evidence still shows the domain reachable; 4 months has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
Jump to section
formexora.com — Dernier actif connu (HTTP 200). Type d'arnaque : Generic Phishing. Résumé des preuves: VirusTotal 6/91 (alphaMountain.ai, Chong Lua Dao, CRDF, CyRadar, Fortinet); URLQuery 1 alert; Spamhaus DBL_SPAM; PhishDestroy score 80/100. Bureau d’enregistrement: Ultahost.
L’analyse détaillée de PhishDestroy AI reste en anglais afin de préserver le relevé forensique original.
Evidence Digest
formexora.com has a stored critical classification with an evidence score of 80/100. 6 of 91 security engines flagged the domain. Registered 5 Sep 2025 via Ultahost, Inc., hosted on 79.133.41.61 (Ultahost, Inc., DE). The latest stored check on 9 Aug 2026 returned HTTP 200 and includes a capture. 1 outgoing abuse report is recorded, most recently on 18 Mar 2026.
Stored generated summary (templated)mistral · 12/07/2026
Retained for the record. This text repeats stored detection facts and is not presented as authored analysis.
This domain, formexora.com, is flagged as an active phishing site targeting individuals seeking septic tank cleaning services in Kyiv, Ukraine. The page title, 'Викачка вигрібних ям Київ | Замовити ☎️ +38 067 007 0068,' directly references a local service, suggesting an attempt to deceive users into engaging with fraudulent contact details. The domain was registered on September 5, 2025, through Ultahost, Inc., and currently resolves to the IP address 79.133.41.61, hosted in Germany under the same provider. Analysis indicates the site employs a 301 HTTP redirect, a common technique to obscure the final destination or evade detection by automated scanners. Infrastructure analysis reveals the domain uses four nameservers (ns1.ultahost.com, ns2.ultahost.com, ns3.ultahost.com, ns4.ultahost.com) and an MX record pointing to itself, which may facilitate email-based phishing attempts. The SSL certificate is issued by Let's Encrypt, a legitimate but frequently abused certificate authority in phishing campaigns due to its free and automated issuance process. The domain appears on at least one security blocklist, specifically PhishDestroy, and is flagged by 6 out of 95 security vendors on VirusTotal, confirming its malicious classification. The risk level for this domain is assessed as high due to its active status, confirmed presence on security blocklists, and targeting of a specific regional service. Defenders should prioritize blocking the domain and its resolving IP address (79.133.41.61) at the network level. Monitoring for related domains registered through Ultahost or sharing the same nameserver infrastructure may help identify additional threats. While the exact phishing kit or payload remains unconfirmed, the domain's structure and behavior align with generic phishing campaigns designed to harvest personal or financial information under the guise of legitimate services.
Couverture des données12 recorded checks
Renseignements sur la sécurité réseau
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Private YARA rules | maps.googleapis.com/maps-api-v3/api/js/64/4d/intl/uk_all/common.js |
audit | Hunting_JS_WebAssembly |
Processus de réponse aux menaces Pipeline
Statut de la liste de blocage publique
Capture enregistrée
Informations sur les domaines
Détails techniquesDNS, SAN SSL, horodatages
ICANN OVERSIGHT
Contexte de l’accréditation et du RAA
Contexte de l’accréditation et du RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Analyse VirusTotal
Analyse des performances du site
Google PageSpeed Insights — mobile performance audit of formexora.com · checked Mar 28, 2026
Données factuelles et rapports externesIndependent lookups and source reports
PD-20260318-16BD93 Recipient: abuse@first-colo.net Victim safety and official reportingImmediate actions and verified reporting channels
Si vous avez saisi des informations d'identification de compte, des informations personnelles ou de paiement, ou téléchargé un fichier à partir de ce domaine, agissez immédiatement. Vous trouverez ci-dessous des ressources pour vous aider à signaler l'incident et à vous protéger.
Signalez-le à vos autorités locales
Sélectionnez votre pays pour obtenir contacts officiels en matière de cybercriminalité ou créer un projet de plainte →.