1952255[.]com
“1952255.com”
संग्रहीत अवलोकन
देखा गया शीर्षक अंतर
साक्ष्य सारांश
This domain, 1952255.com, operates as a credential harvesting phishing site designed to deceive users into submitting login credentials, financial details, or other sensitive information. The site typically mimics legitimate services or login portals, presenting fake forms that capture entered data and transmit it to malicious actors. Such attacks can lead to unauthorized account access, identity theft, or financial fraud, with potential downstream effects including lateral movement in corporate networks or further phishing campaigns targeting contacts of compromised users. Analysis indicates the domain has been flagged by 21 out of 95 security vendors on VirusTotal, reflecting broad consensus on its malicious nature. The domain was registered on January 6, 2019, through GoDaddy.com, LLC, and resolves to the IP address 198.18.0.212, hosted in Hong Kong under autonomous system AS135581. Infrastructure review shows the SSL certificate is issued to 'Default Company Ltd,' a common indicator of low-effort malicious infrastructure. The domain appears on one security blocklist and has been taken offline, though its historical activity remains a concern for retrospective threat hunting. Users who visited 1952255.com should assume potential exposure of any entered credentials. Immediately reset passwords for accounts accessed from the same device or network during the exposure window, prioritizing email, financial, and work-related accounts. Enable multi-factor authentication (MFA) where available to mitigate unauthorized access. Scan the device for malware using updated security tools, focusing on browser-based threats or keyloggers. Review account activity for unauthorized logins or transactions, and report any suspicious findings to relevant security teams or service providers. Organizations should check logs for connections to 198.18.0.212 or DNS queries for 1952255.com to identify potentially compromised endpoints.
Data Coverage
सुरक्षा संकेत
नेटवर्क सुरक्षा इंटेलिजेंस
धमकी प्रतिक्रिया पाइपलाइन
ब्लॉकलिस्ट कवरेज
10 निगरानी वाले बाहरी स्रोत · संग्रहीत स्नैपशॉट 10/08/2026
पहचान समयरेखा
-
VirusTotal
19 → 21
-
Cloudflare Radar
Cloudflare Radar स्कैन संग्रहीत · स्कैन खोलें
सहेजा गया कैप्चर
डोमेन इंटेलिजेंस
तकनीकी विवरणDNS, TLS नाम और समय-मुद्राएँ
ICANN OVERSIGHT
प्रत्यायन और आरएए संदर्भ
प्रत्यायन और आरएए संदर्भ
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
वायरसटोटल विश्लेषण
क्या आप इस साइट से प्रभावित हुए?
यदि आपने खाता क्रेडेंशियल, व्यक्तिगत या भुगतान जानकारी दर्ज की है, या इस डोमेन से कोई फ़ाइल डाउनलोड की है, तो तुरंत कार्रवाई करें। घटना की रिपोर्ट करने और अपनी सुरक्षा करने में आपकी सहायता के लिए नीचे संसाधन दिए गए हैं।
अपने स्थानीय अधिकारियों को रिपोर्ट करें
आधिकारिक साइबर अपराध संपर्क, या एक शिकायत ड्राफ्ट बनाएं → प्राप्त करने के लिए अपना देश चुनें।
किसी भी डोमेन की जाँच करें
संग्रहीत ब्लॉकलिस्ट, WHOIS, DNS और सार्वजनिक स्कैन साक्ष्य का उपयोग करके खतरे का विश्लेषण
अभी स्कैन करेंफ़िशिंग की रिपोर्ट करें
संदिग्ध डोमेन हमारे थ्रेट डेटाबेस में जमा करें — समुदाय की सुरक्षा करें
रिपोर्ट करेंसीधा खतरा फीड
हाल की फ़िशिंग रिपोर्टें और उपलब्धता में परिवर्तन देखे गए
निगरानी करेंजानकारी में रहें, सुरक्षित रहें
लाइव खतरों की निगरानी करें या यदि आपको लगता है कि यह एक गलत सकारात्मक है तो इस लिस्टिंग को चुनौती दें।