सुरक्षा रिपोर्ट पर जाएँ
⚠️
इस डोमेन को दुर्भावनापूर्ण के रूप में चिह्नित किया गया है।
सुरक्षा इंजन एक पहचान की रिपोर्ट कर रहे हैं: 15। अत्यधिक सावधानी बरतें - क्रेडेंशियल या व्यक्तिगत जानकारी दर्ज न करें।
ABUSE NOTICE · 7D+ OPEN Outgoing abuse reports are recorded; the latest stored availability evidence still shows the domain reachable.
Notification and current-status evidence

The sent-report ledger records the first outgoing report at . The recorded recipient is complaint@gname.com. The latest stored availability evidence still shows the domain reachable; 5 months has elapsed since the first outgoing report.

ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.

Elapsed since first report
5 months
Reports sent
1
Latest case ID
PD-20260219-42CF6B
Current status
Observed active at latest stored check
डोमेन सुरक्षा और ख़तरे की आसूचना

cafekessabine[.]com

“im冷钱包下载_imtoken官方下载”

धमकी भरा फैसला गंभीर 95/100 साक्ष्य स्कोर
उपलब्धता असत्यापित वर्तमान पहुंच योग्यता असत्यापित है
वायरस का कुल पता लगाना: 15/91 URLQuery threat systems: 2 alerts ब्रांड प्रतिरूपण: ImToken
19/02/2026 ImToken 1 Report Sent
रिपोर्ट सारांश

cafekessabine.com — असत्यापित. ब्रांड प्रतिरूपण: ImToken; घोटाले का प्रकार: Brand Impersonation. साक्ष्य सारांश: VirusTotal 15/91 (ADMINUSLabs, alphaMountain.ai, BitDefender, CRDF, CyRadar); URLQuery 2 alerts; URLScan malicious verdict; PhishDestroy score 95/100. रजिस्ट्रार: Gname.

मूल फॉरेंसिक रिकॉर्ड सुरक्षित रखने के लिए नीचे का विस्तृत PhishDestroy AI विश्लेषण अंग्रेज़ी में रखा गया है।

साक्ष्य सारांश
आलोचनात्मक
संदर्भ
59AEE61D
स्कोर
95/100

Analysis of cafekessabine.com, first observed on February 21 2026, shows a high‑risk brand‑impersonation campaign targeting users of the cryptocurrency wallet service imToken. The site serves an HTTP 200 response and presents the page title “im冷钱包下载_imtoken官方下载”, directly referencing the imToken brand in Chinese. Technical headers reveal the use of Nginx as the web server, with modern features such as HTTP/3 and HSTS enabled, and client‑side libraries including jQuery. The domain resolves to IP address 45.207.200.158, which is allocated to FASTNET DATA INC in the United States (ASN 8796).

DNS resolution is handled by the shared name servers a2.share-dns.com and b2.share-dns.net, a pattern often seen in malicious hosting. The SSL certificate is issued by Let’s Encrypt (R12), providing encrypted transport but offering no indication of legitimacy. Reputation services flag the domain: it appears on one public blocklist, PhishDestroy, and 15 of 93 VirusTotal scanners label it malicious, while Gridinsoft assigns a trust score of 0 / 100. The registrar listed is Gname.com Pte. Ltd., a provider frequently used for disposable registrations.

Although the page content has not been publicly dissected, the combination of brand‑specific title, active hosting, and multiple security vendor detections strongly suggests a phishing site designed to lure imToken users into downloading a counterfeit wallet. Defenders should block DNS resolution for cafekessabine.com, add the associated IP 45.207.200.158 to deny‑list rules, and monitor for any traffic attempts to the domain or its name servers. Users should be warned not to trust any download links or credential prompts associated with this domain, and security teams should update web‑filter and email‑gateway signatures to include the observed indicators.

VirusTotal
VirusTotal
15 det.
URLQuery
यूआरएलक्वेरी
2 threat alerts
URLScan
यूआरएलस्कैन
ScamAdviser
Scamadviser
65/100
TLS प्रमाणपत्र
R12
देखी गई स्थिति
असत्यापित
PhishDestroy
विनाश सूची
सूचीबद्ध
Reports Sent
1
डेटा कवरेज VirusTotal 15 / 91 यूआरएलक्वेरी 2 threat-system alerts फ़िशस्टैट्स checked — no match recorded ओटीएक्स no community references सीएफ रडार scan completed URLScan capture संग्रहित रिपोर्ट URLScan verdict malicious डीएनएस ब्लॉक 15 जाँच पूरी — कोई ब्लॉक नहीं TLS valid certificate, 58d कौन है not parsed स्क्रीनशॉट 3 captures · 3 sources चेन पुनर्निर्देशित करें जांच नहीं की गई Scamadviser 65/100
सुरक्षा संकेत
SA Scamadviser Warnings 65/100
The owner of the website is using a service to hide their identity on WHOIS This website is not optimized for search engines High number of suspicious websites on this server This site is using keywords that may be related to scams This website seems to be parked (how to get your money back)
This website is (very) old
नेटवर्क सुरक्षा इंटेलिजेंस
Threat Detection Systems 2 alerts
Detection System Indicator Verdict Alert
OpenDNS cafekessabine.com phishing Phishing Block
DNS4EU cafekessabine.com malicious Sinkholed

धमकी प्रतिक्रिया पाइपलाइन

खोज
Checks
Reports
उपलब्धता
12/13
Sent Report Recorded
Stored sent-report record for registrar Gname.com Pte. Ltd., hosting provider, 1 abuse contact
complaint@gname.com
19/02/2026

सार्वजनिक ब्लॉकलिस्ट स्थिति

सहेजा गया कैप्चर

पेज शीर्षक
im冷钱包下载_imtoken官方下载
TLS प्रमाणपत्र
Valid transport encryption · जारीकर्ता R12 · valid for 58 days

डोमेन इंटेलिजेंस

डोमेन
URLScan Verdict दुर्भावनापूर्ण score 100 Phishing brand: Imtoken report ↗
सर्वर / ASN nginx · AS8796 FASTNET DATA INC
IP प्रतिष्ठा abuse score 0/100 0 reports checked 15/07/2026
रजिस्ट्रार Gname SG(SG)
दुरुपयोग संपर्कcomplaint@gname.com
IP पता 45.207.200.158 US
भौगोलिक स्थानUS Los Angeles, US
नेटवर्कAS8796 · FASTNET DATA INC
रिवर्स IPviewdns.info → rapiddns.io →
Elapsed Since First Report 24 days
हम क्या मापते हैं Raw elapsed time since the first stored abuse report. It is not a registrar response-time measurement. Latest observed status: असत्यापित.
प्रत्येक रिपोर्ट में क्या शामिल है संग्रहीत आउटगोइंग-रिपोर्ट रिकॉर्ड उस समय उपलब्ध साक्ष्य का संदर्भ दे सकते हैं, जैसे विक्रेता के फैसले, पंजीकरण डेटा, होस्टिंग विवरण, वर्गीकरण, या स्क्रीनशॉट। यह पृष्ठ किसी प्राप्तकर्ता द्वारा वितरित सटीक पेलोड, रसीद, पावती या कार्रवाई का अनुमान नहीं लगाता है।
तकनीकी विवरणडीएनएस, एसएसएल एसएएन, टाइमस्टैम्प
पहली बार पता चला19/02/2026
DOM Analysisanalyzed 10/07/2026score 88/100
IoC Extractionscanned 29/07/20260 wallet · 0 Telegram IoCs
Submitted URLhttps://cafekessabine.com/
नेमसर्वरb2.share-dns.net
TLS Observationvalid from 27/01/2026scanned 15/03/2026
Favicon Hash
Case ID
ICANN OVERSIGHT

प्रत्यायन और आरएए संदर्भ

Registrar accreditation and DNS abuse obligations

For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.

Accreditation is a contract, not a safety certification.

RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.

मान्यता एक अनुबंध है, सुरक्षा की मुहर नहीं। ICANN शुल्क सत्यापित करें RAA §3.18 पढ़ें PHISHDESTROY INVESTIGATIONICANN funding, contracts, and DNS abuse oversight
Accountability draft कुछ भी अपने आप नहीं भेजा जाता।
तकनीकें · 4 identified
Nginx
Web servers Reverse proxies

High-performance HTTP server and reverse proxy, known for stability and low resource usage.

jQuery
JavaScript libraries

Fast, small JavaScript library simplifying HTML manipulation, event handling, and Ajax.

HSTS
सुरक्षा

HTTP Strict Transport Security — forces browsers to use HTTPS connections only.

HTTP/3
Miscellaneous

Third major version of HTTP protocol, built on QUIC for faster, more reliable connections.

Detected via क्लाउडफ्लेयर रडार · Wappalyzer engine
इस डोमेन की रिपोर्ट करें सबूत जमा करें और दूसरों की सुरक्षा में मदद करें

वायरसटोटल विश्लेषण

15 / 91 सुरक्षा विक्रेताओं ने इस डोमेन को चिह्नित किया
View on VT
Last analyzed Previous stored snapshot: 15 detections
ADMINUSLabs
alphaMountain.ai
BitDefender
CRDF
साइरेडार
Emsisoft
Fortinet
G-Data
Gridinsoft
कास्परस्की
Lionic
नेटक्राफ्ट
सोफोस
VIPRE
वेबरूट

संग्रहीत साक्ष्य

Wayback Machine Snapshot
साक्ष्य समीक्षा के लिए एक ऐतिहासिक स्नैपशॉट उपलब्ध है
View Archive

साक्ष्य और बाहरी रिपोर्टें

Submitted Evidence Snapshot
Sent: Ledger records: 1 Case ID: PD-20260219-42CF6B Recipient: complaint@gname.com
Page title stored with report: im冷钱包下载_imtoken官方下载
URLScan evidence VirusTotal evidence URLQuery evidence Screenshot 56.1 KB

क्या आप इस साइट से प्रभावित हुए?

If credentials were compromised, report immediately. Do not engage with recovery scammers.

यदि आपने खाता क्रेडेंशियल, व्यक्तिगत या भुगतान जानकारी दर्ज की है, या इस डोमेन से कोई फ़ाइल डाउनलोड की है, तो तुरंत कार्रवाई करें। घटना की रिपोर्ट करने और अपनी सुरक्षा करने में आपकी सहायता के लिए नीचे संसाधन दिए गए हैं।

यूरोपोल
अपने ईयू देश के लिए आधिकारिक रिपोर्टिंग चैनल ढूंढें
National police directory
रिकवरी ठगों से सावधान रहें! अपराधी जांचकर्ता, वकील या रिकवरी एजेंट होने का नाटक करते हुए पीड़ितों से दोबारा संपर्क कर सकते हैं। अग्रिम शुल्क का भुगतान न करें या क्रेडेंशियल साझा न करें। रिकवरी धोखाधड़ी के बारे में और जानें →

अपने स्थानीय अधिकारियों को रिपोर्ट करें

आधिकारिक साइबर अपराध संपर्क, या एक शिकायत ड्राफ्ट बनाएं → प्राप्त करने के लिए अपना देश चुनें।

97-देश निर्देशिका
एआई-सहायता प्राप्त ड्राफ्ट - घटना विवरण एआई प्रदाता द्वारा संसाधित किया जाता है इसकी स्वयं समीक्षा करें और सबमिट करें

किसी भी डोमेन की जाँच करें

संग्रहीत ब्लॉकलिस्ट, WHOIS, DNS और सार्वजनिक स्कैन साक्ष्य का उपयोग करके खतरे का विश्लेषण

अभी स्कैन करें

फ़िशिंग की रिपोर्ट करें

संदिग्ध डोमेन हमारे थ्रेट डेटाबेस में जमा करें — समुदाय की सुरक्षा करें

रिपोर्ट करें

सीधा खतरा फीड

हाल की फ़िशिंग रिपोर्टें और उपलब्धता में परिवर्तन देखे गए

निगरानी करें

जानकारी में रहें, सुरक्षित रहें

लाइव खतरों की निगरानी करें या यदि आपको लगता है कि यह एक गलत सकारात्मक है तो इस लिस्टिंग को चुनौती दें।

सीधा खतरा फीड इस लिस्टिंग के खिलाफ अपील करें
HTML · IFRAME

इस रिपोर्ट को एम्बेड करें

इस थ्रेट इंटेलिजेंस को अपनी वेबसाइट या ब्लॉग पर साझा करें।

embed.html
<iframe
  src="https://phishdestroy.io/hi/embed/domain/cafekessabine.com"
  title="PhishDestroy threat report for cafekessabine.com"
  width="100%" height="320"
  loading="lazy"
  referrerpolicy="no-referrer"
  sandbox="allow-same-origin allow-popups allow-popups-to-escape-sandbox"
  style="border:0;border-radius:12px;max-width:100%"
></iframe>

एक अत्यंत सच्चा धन्यवाद-पत्र

व्यंग्यात्मक मसौदा जनरेटर

प्राप्तकर्ता
शुल्क संदर्भ

यह व्यंग्यात्मक मसौदा है। शुल्क के आंकड़े अनुमान हैं; इन्हें इस डोमेन से ठीक-ठीक जोड़ने का दावा नहीं किया जाता।