connexpay-app[.]co[.]com
“ConnexPay Login | B2B Payments Solution | Login - ConnexPay”
साक्ष्य सारांश
Analysis of the domain connexpay-app.co.com, observed on July 24, 2026, indicates a high‑risk credential phishing campaign targeting the ConnexPay brand. The site’s page title explicitly advertises a ConnexPay login portal, confirming the intended victim set. The domain resolves to the IP address 144.31.244.50, which is registered to AS213877 U1 DIGITAL SERVICES LTD and geolocated in Germany. Registration data show the domain was created on August 16, 1997 and is serviced by the registrar Moniker Online Services LLC, with a diverse set of nameservers (ns1.nic.co.com, ns2.nic.co.com, ns3.my-ndns.com, ns3.nic.co.com, ns4.my-ndns.com, ns4). No SSL certificate is present, and the site is currently taken offline, limiting immediate access for verification.
VirusTotal records indicate that 16 of 95 security vendors have flagged the domain, reinforcing the malicious assessment. The domain appears on four public blocklists and is specifically listed by PhishDestroy, Polkadot, Enkrypt, and Codeesura, demonstrating consensus among threat‑intelligence feeds. Reputation services assign extremely low scores: Scamadviser rates it 1 / 100 and Gridinsoft 0 / 100, reflecting a lack of legitimacy. The classification as credential phishing is corroborated by the page title and blocklist tags.
Uncertainties remain regarding the exact phishing kit used and any additional infrastructure that may have been employed before takedown, as no further forensic artifacts are publicly disclosed. Defenders should add the domain, its associated IP, and the full nameserver set to their block and detection rules, monitor for any re‑registration attempts, and enforce strict credential monitoring for ConnexPay accounts. Network traffic to the IP should be flagged, and any inbound connections to the listed nameservers treated as suspicious. Continuous review of blocklist updates is recommended to capture potential resurgence of the infrastructure.
Data Coverage
सुरक्षा संकेत
धमकी प्रतिक्रिया पाइपलाइन
ब्लॉकलिस्ट कवरेज
10 निगरानी वाले बाहरी स्रोत · संग्रहीत स्नैपशॉट 12/08/2026
7 निगरानी वाले बाहरी स्रोत कोई मिलान नहीं
पहचान समयरेखा
-
Cloudflare Radar
Cloudflare Radar स्कैन संग्रहीत · स्कैन खोलें
फॉरेंसिक इंटेलिजेंस
वायरसटोटल विश्लेषण
क्या आप इस साइट से प्रभावित हुए?
यदि आपने खाता क्रेडेंशियल, व्यक्तिगत या भुगतान जानकारी दर्ज की है, या इस डोमेन से कोई फ़ाइल डाउनलोड की है, तो तुरंत कार्रवाई करें। घटना की रिपोर्ट करने और अपनी सुरक्षा करने में आपकी सहायता के लिए नीचे संसाधन दिए गए हैं।
अपने स्थानीय अधिकारियों को रिपोर्ट करें
आधिकारिक साइबर अपराध संपर्क, या एक शिकायत ड्राफ्ट बनाएं → प्राप्त करने के लिए अपना देश चुनें।
किसी भी डोमेन की जाँच करें
संग्रहीत ब्लॉकलिस्ट, WHOIS, DNS और सार्वजनिक स्कैन साक्ष्य का उपयोग करके खतरे का विश्लेषण
अभी स्कैन करेंफ़िशिंग की रिपोर्ट करें
संदिग्ध डोमेन हमारे थ्रेट डेटाबेस में जमा करें — समुदाय की सुरक्षा करें
रिपोर्ट करेंसीधा खतरा फीड
हाल की फ़िशिंग रिपोर्टें और उपलब्धता में परिवर्तन देखे गए
निगरानी करेंजानकारी में रहें, सुरक्षित रहें
लाइव खतरों की निगरानी करें या यदि आपको लगता है कि यह एक गलत सकारात्मक है तो इस लिस्टिंग को चुनौती दें।