सुरक्षा रिपोर्ट पर जाएँ
⚠️
इस डोमेन को दुर्भावनापूर्ण के रूप में चिह्नित किया गया है।
सुरक्षा इंजन एक पहचान की रिपोर्ट कर रहे हैं: 14। अत्यधिक सावधानी बरतें - क्रेडेंशियल या व्यक्तिगत जानकारी दर्ज न करें।
डोमेन सुरक्षा और ख़तरे की आसूचना

att[.]ciowu[.]icu

“Welcome to nginx!”

धमकी भरा फैसला गंभीर 95/100 साक्ष्य स्कोर
उपलब्धता सामग्री अनुपलब्ध नवीनतम अवलोकन में सामग्री अनुपलब्ध थी
वायरस का कुल पता लगाना: 14/93 Spamhaus DBL: DBL_PHISH URLQuery threat systems: 1 alert
28/01/2026 1 Report Sent CDN
रिपोर्ट सारांश

att.ciowu.icu — सामग्री अनुपलब्ध. साक्ष्य सारांश: VirusTotal 14/93 (Criminal IP, alphaMountain.ai, Chong Lua Dao, Cluster25, CRDF); URLQuery 1 alert; Spamhaus DBL_PHISH; PhishDestroy score 95/100. रजिस्ट्रार: Gname.

मूल फॉरेंसिक रिकॉर्ड सुरक्षित रखने के लिए नीचे का विस्तृत PhishDestroy AI विश्लेषण अंग्रेज़ी में रखा गया है।

साक्ष्य सारांश
आलोचनात्मक
संदर्भ
D1EFF256
स्कोर
95/100

att.ciowu.icu was observed returning the default nginx page title “Welcome to nginx!” before being taken offline. The domain was registered on February 21, 2026 through Gname.com Pte. Ltd. and is hosted on Cloudflare infrastructure (nameservers brady.ns.cloudflare.com and love.ns.cloudflare.com). DNS resolution points to 188.114.97.3, an address owned by AS13335 Cloudflare, Inc., located in the United States. No TLS certificate is presented, indicating the site was served over plain HTTP.

The site is classified as a brand‑impersonation campaign targeting x.com, and the Gridinsoft trust score is 0/100, reflecting a complete lack of trust. PhishDestroy has already blocked the domain, and it appears on at least one public security blocklist. VirusTotal analysis shows that 14 of 93 scanning engines flagged the domain as malicious, reinforcing the suspicion of phishing activity.

Current status is offline, so active payloads cannot be confirmed, but the combination of low trust score, blocklist presence, and vendor detections strongly suggests a fraudulent site designed to lure victims into providing credentials for x.com. Defenders should continue to denylist att.ciowu.icu and its resolving IP, monitor the Cloudflare‑hosted address for re‑use, and consider adding the domain to internal URL filtering rules. Ongoing observation of the registrar Gname.com Pte. Ltd. for similar registrations is advisable, as is periodic re‑scanning to detect any re‑activation.

VirusTotal
VirusTotal
14 det.
URLQuery
यूआरएलक्वेरी
1 threat alert
URLScan
यूआरएलस्कैन
देखी गई स्थिति
सामग्री अनुपलब्ध
PhishDestroy
विनाश सूची
सूचीबद्ध
Reports Sent
1
डेटा कवरेज VirusTotal 14 / 93 यूआरएलक्वेरी 1 threat-system alert फ़िशस्टैट्स जाँच नहीं की गई ओटीएक्स no community references सीएफ रडार scan completed URLScan capture संग्रहित रिपोर्ट URLScan verdict निष्कर्ष उपलब्ध नहीं डीएनएस ब्लॉक जाँच नहीं की गई TLS कोई प्रमाणपत्र डेटा नहीं कौन है not parsed स्क्रीनशॉट 3 captures · 3 sources चेन पुनर्निर्देशित करें जांच नहीं की गई
नेटवर्क सुरक्षा इंटेलिजेंस
Threat Detection Systems 1 alert
Detection System Indicator Verdict Alert
Quad9 DNS att.ciowu.icu malicious Sinkholed

धमकी प्रतिक्रिया पाइपलाइन

खोज
Checks
Reports
उपलब्धता
12/12
Sent Report Recorded
Stored sent-report record for registrar Gname.com Pte. Ltd., hosting provider, 1 abuse contact
complaint@gname.com
28/01/2026

सार्वजनिक ब्लॉकलिस्ट स्थिति

सहेजा गया कैप्चर

पेज शीर्षक
Welcome to nginx!

डोमेन इंटेलिजेंस

डोमेन
सर्वर / ASN cloudflare · AS13335 CLOUDFLARENET - Cloudflare, Inc., US
IP Context Cloudflare shared edge origin IP hidden एज-आईपी प्रतिष्ठा इस डोमेन के लिए जिम्मेदार नहीं है।
Registrar (base domain) Gname SG(SG)
दुरुपयोग संपर्कcomplaint@gname.com
IP पता 188.114.97.3 CDN
भौगोलिक स्थानUS San Francisco, US
नेटवर्कAS13335 · Cloudflare, Inc.
रिवर्स IPviewdns.info → rapiddns.io →
मूल आईपी सीडीएन प्रॉक्सी के पीछे छिपा हुआ है। किनारे के पते के लिए रिवर्स-आईपी परिणामों में असंबंधित किरायेदार शामिल हैं; मूल का पता लगाने के लिए निष्क्रिय DNS या प्रमाणपत्र-पारदर्शिता डेटा की आवश्यकता होती है।
Registration (base domain)ciowu.icu · Expires 20/01/2027
पहली अनुपलब्धता तक का समय 101 days
हम क्या मापते हैं पहली संग्रहीत दुरुपयोग रिपोर्ट से लेकर पहली बार अवलोकन तक कि सामग्री अनुपलब्ध थी, बीता हुआ समय। इससे कारण स्थापित नहीं होता.
प्रत्येक रिपोर्ट में क्या शामिल है संग्रहीत आउटगोइंग-रिपोर्ट रिकॉर्ड उस समय उपलब्ध साक्ष्य का संदर्भ दे सकते हैं, जैसे विक्रेता के फैसले, पंजीकरण डेटा, होस्टिंग विवरण, वर्गीकरण, या स्क्रीनशॉट। यह पृष्ठ किसी प्राप्तकर्ता द्वारा वितरित सटीक पेलोड, रसीद, पावती या कार्रवाई का अनुमान नहीं लगाता है।
तकनीकी विवरणडीएनएस, एसएसएल एसएएन, टाइमस्टैम्प
पहली बार पता चला28/01/2026
DOM Analysisanalyzed 23/04/2026score 10/100
IoC Extractionscanned 02/08/20260 wallet · 0 Telegram IoCs
Submitted URLhttp://att.ciowu.icu/
नेमसर्वरbrady.ns.cloudflare.comlove.ns.cloudflare.com
TLS Observationscanned 15/03/2026
Case ID
SHORTDOT ज़ोन · सार्वजनिक साक्ष्य .icu

ShortDot zone evidence

The linked repository preserves daily zone observations across seven ShortDot-operated TLDs, including registration volume and abuse-related indicators. This registry context is supporting background and is not an independent detection for the domain in this report.

ShortDot SA · Luxembourg 7 ज़ोन · पूरे ज़ोन के साक्ष्य प्रतिदिन अपडेट किए जाते हैं ShortDot साक्ष्य रिपॉज़िटरी खोलें
ICANN OVERSIGHT Registration: ciowu.icu

प्रत्यायन और आरएए संदर्भ

Registrar accreditation and DNS abuse obligations

For the registrable domain ciowu.icu behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.

Accreditation is a contract, not a safety certification.

RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.

मान्यता एक अनुबंध है, सुरक्षा की मुहर नहीं। ICANN शुल्क सत्यापित करें RAA §3.18 पढ़ें PHISHDESTROY INVESTIGATIONICANN funding, contracts, and DNS abuse oversight
Accountability draft कुछ भी अपने आप नहीं भेजा जाता।
इस डोमेन की रिपोर्ट करें सबूत जमा करें और दूसरों की सुरक्षा में मदद करें

वायरसटोटल विश्लेषण

14 / 93 सुरक्षा विक्रेताओं ने इस डोमेन को चिह्नित किया
View on VT
Last analyzed
Criminal IP
alphaMountain.ai
Chong Lua Dao
Cluster25
CRDF
साइरेडार
ईएसईटी
Fortinet
Gridinsoft
Lionic
MalwareURL
SOCRadar
VIPRE
वेबरूट

साक्ष्य और बाहरी रिपोर्टें

Submitted Evidence Snapshot
Sent: Ledger records: 1 Case ID: PD-20260128-B95781 Recipient: complaint@gname.com
Page title stored with report: Welcome to nginx!
URLScan evidence VirusTotal evidence URLQuery evidence Screenshot 14.8 KB

क्या आप इस साइट से प्रभावित हुए?

If credentials were compromised, report immediately. Do not engage with recovery scammers.

यदि आपने खाता क्रेडेंशियल, व्यक्तिगत या भुगतान जानकारी दर्ज की है, या इस डोमेन से कोई फ़ाइल डाउनलोड की है, तो तुरंत कार्रवाई करें। घटना की रिपोर्ट करने और अपनी सुरक्षा करने में आपकी सहायता के लिए नीचे संसाधन दिए गए हैं।

यूरोपोल
अपने ईयू देश के लिए आधिकारिक रिपोर्टिंग चैनल ढूंढें
National police directory
रिकवरी ठगों से सावधान रहें! अपराधी जांचकर्ता, वकील या रिकवरी एजेंट होने का नाटक करते हुए पीड़ितों से दोबारा संपर्क कर सकते हैं। अग्रिम शुल्क का भुगतान न करें या क्रेडेंशियल साझा न करें। रिकवरी धोखाधड़ी के बारे में और जानें →

अपने स्थानीय अधिकारियों को रिपोर्ट करें

आधिकारिक साइबर अपराध संपर्क, या एक शिकायत ड्राफ्ट बनाएं → प्राप्त करने के लिए अपना देश चुनें।

97-देश निर्देशिका
एआई-सहायता प्राप्त ड्राफ्ट - घटना विवरण एआई प्रदाता द्वारा संसाधित किया जाता है इसकी स्वयं समीक्षा करें और सबमिट करें

किसी भी डोमेन की जाँच करें

संग्रहीत ब्लॉकलिस्ट, WHOIS, DNS और सार्वजनिक स्कैन साक्ष्य का उपयोग करके खतरे का विश्लेषण

अभी स्कैन करें

फ़िशिंग की रिपोर्ट करें

संदिग्ध डोमेन हमारे थ्रेट डेटाबेस में जमा करें — समुदाय की सुरक्षा करें

रिपोर्ट करें

सीधा खतरा फीड

हाल की फ़िशिंग रिपोर्टें और उपलब्धता में परिवर्तन देखे गए

निगरानी करें

जानकारी में रहें, सुरक्षित रहें

लाइव खतरों की निगरानी करें या यदि आपको लगता है कि यह एक गलत सकारात्मक है तो इस लिस्टिंग को चुनौती दें।

सीधा खतरा फीड इस लिस्टिंग के खिलाफ अपील करें
HTML · IFRAME

इस रिपोर्ट को एम्बेड करें

इस थ्रेट इंटेलिजेंस को अपनी वेबसाइट या ब्लॉग पर साझा करें।

embed.html
<iframe
  src="https://phishdestroy.io/hi/embed/domain/att.ciowu.icu"
  title="PhishDestroy threat report for att.ciowu.icu"
  width="100%" height="320"
  loading="lazy"
  referrerpolicy="no-referrer"
  sandbox="allow-same-origin allow-popups allow-popups-to-escape-sandbox"
  style="border:0;border-radius:12px;max-width:100%"
></iframe>

एक अत्यंत सच्चा धन्यवाद-पत्र

व्यंग्यात्मक मसौदा जनरेटर

प्राप्तकर्ता
शुल्क संदर्भ

यह व्यंग्यात्मक मसौदा है। शुल्क के आंकड़े अनुमान हैं; इन्हें इस डोमेन से ठीक-ठीक जोड़ने का दावा नहीं किया जाता।