Notification and current-status evidence
The sent-report ledger records the first outgoing report at .
The recorded recipient is abuse@bluehost.com.
The latest stored availability evidence still shows the domain reachable; 1 month has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
azfit[.]com[.]br
“Document Access Portal”
azfit.com.br — ढका हुआ · पहुंच योग्य. ब्रांड प्रतिरूपण: Genericemail; घोटाले का प्रकार: Generic Phishing. साक्ष्य सारांश: VirusTotal 15/91 (alphaMountain.ai, BitDefender, Chong Lua Dao, Cluster25, CyRadar); URLScan malicious verdict; cloaking observed; PhishDestroy score 100/100.
मूल फॉरेंसिक रिकॉर्ड सुरक्षित रखने के लिए नीचे का विस्तृत PhishDestroy AI विश्लेषण अंग्रेज़ी में रखा गया है।
The domain azfit.com.br hosts a site presenting itself as a "Document Access Portal," a generic label often used in credential harvesting or phishing lures. The site poses a security threat by employing cloaking techniques, specifically content_divergence, which indicates it serves different content to crawlers versus visitors, a common evasion tactic. Its association with WordPress, cdnjs, and Font Awesome suggests a potential compromised installation used for malicious purposes.
Technical analysis shows the domain has a VirusTotal score of 5/95 detections, flagged by alphaMountain.ai, Chong Lua Dao, Forcepoint ThreatSeeker, SOCRadar, and Webroot, and appears on one blocklist. The domain was created on 2021-12-08, uses a REGISTRAR_NOT_FOUND registrar, and resolves to IP 162.241.203.111 in Brazil, assigned to AS31898 Oracle Corporation. The SSL certificate is issued by Let's Encrypt with identifier YR1, and nameservers are ns258.prodns.com.br and ns259.prodns.com.br.
The site is currently DOWN/OFFLINE, which may indicate takedown or inactivity. The DOM risk score is 78, signifying a high risk level. The combination of cloaking detection, multiple security vendor flags, and generic portal title strongly suggests this domain was used for malicious document-themed phishing or credential theft.
धमकी प्रतिक्रिया पाइपलाइन
सार्वजनिक ब्लॉकलिस्ट स्थिति
थ्रेट इंटेलिजेंस क्रॉस-रेफ़रेंस · source references
वायरसटोटल विश्लेषण
साइट कॉन्फ़िगरेशन विश्लेषण
साक्ष्य और बाहरी रिपोर्टें
PD-20260623-944651 Recipient: abuse@bluehost.com क्या आप इस साइट से प्रभावित हुए?
यदि आपने खाता क्रेडेंशियल, व्यक्तिगत या भुगतान जानकारी दर्ज की है, या इस डोमेन से कोई फ़ाइल डाउनलोड की है, तो तुरंत कार्रवाई करें। घटना की रिपोर्ट करने और अपनी सुरक्षा करने में आपकी सहायता के लिए नीचे संसाधन दिए गए हैं।
अपने स्थानीय अधिकारियों को रिपोर्ट करें
आधिकारिक साइबर अपराध संपर्क, या एक शिकायत ड्राफ्ट बनाएं → प्राप्त करने के लिए अपना देश चुनें।
किसी भी डोमेन की जाँच करें
संग्रहीत ब्लॉकलिस्ट, WHOIS, DNS और सार्वजनिक स्कैन साक्ष्य का उपयोग करके खतरे का विश्लेषण
अभी स्कैन करेंफ़िशिंग की रिपोर्ट करें
संदिग्ध डोमेन हमारे थ्रेट डेटाबेस में जमा करें — समुदाय की सुरक्षा करें
रिपोर्ट करेंसीधा खतरा फीड
हाल की फ़िशिंग रिपोर्टें और उपलब्धता में परिवर्तन देखे गए
निगरानी करेंजानकारी में रहें, सुरक्षित रहें
लाइव खतरों की निगरानी करें या यदि आपको लगता है कि यह एक गलत सकारात्मक है तो इस लिस्टिंग को चुनौती दें।