सुरक्षा रिपोर्ट पर जाएँ
⚠️
इस डोमेन को दुर्भावनापूर्ण के रूप में चिह्नित किया गया है।
सुरक्षा इंजन एक पहचान की रिपोर्ट कर रहे हैं: 5। किसी मैच की रिपोर्ट करने वाली सार्वजनिक ब्लॉक सूचियाँ: 1। अत्यधिक सावधानी बरतें - क्रेडेंशियल या व्यक्तिगत जानकारी दर्ज न करें।
ABUSE NOTICE · 7D+ OPEN Outgoing abuse reports are recorded; the latest stored availability evidence still shows the domain reachable.
Notification and current-status evidence

The sent-report ledger records the first outgoing report at . The recorded recipient is network-abuse@google.com. The latest stored availability evidence still shows the domain reachable; 7 months has elapsed since the first outgoing report.

ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.

Elapsed since first report
7 months
Reports sent
1
Latest case ID
PD-20260104-1A6183
Current status
Observed active at latest stored check
डोमेन सुरक्षा और ख़तरे की आसूचना

correosprepago[.]bnext[.]es

“Mi tarjeta | Correos Prepago”

धमकी भरा फैसला ऊँचा 69/100 साक्ष्य स्कोर
उपलब्धता असत्यापित वर्तमान पहुंच योग्यता असत्यापित है
वायरस का कुल पता लगाना: 5/91 संग्रहीत ब्लॉकलिस्ट मिलान: 1 URLQuery threat systems: 4 alerts घोटाले का प्रकार: Generic Phishing
26/02/2026 1 Report Sent CDN
रिपोर्ट सारांश

correosprepago.bnext.es — असत्यापित. घोटाले का प्रकार: Generic Phishing. साक्ष्य सारांश: VirusTotal 5/91 (ADMINUSLabs, Chong Lua Dao, Gridinsoft, PREBYTES, VIPRE); URLQuery 4 alerts; 1 external blocklist match (Phishunt); PhishDestroy score 69/100. रजिस्ट्रार: Google Domains.

मूल फॉरेंसिक रिकॉर्ड सुरक्षित रखने के लिए नीचे का विस्तृत PhishDestroy AI विश्लेषण अंग्रेज़ी में रखा गया है।

साक्ष्य सारांश
उच्च
संदर्भ
17CA234A
स्कोर
69/100

Analysis of the domain correosprepago.bnext.es indicates that it was registered on February 21, 2026 through Google LLC and is hosted on a Fastly edge network (AS54113) with the IPv6 address 2620:0:890::100. The authoritative nameserver listed is correosprepago.web.app, and the site serves a valid TLS certificate issued by Google Trust Services under the WR3 profile, with HTTP Strict Transport Security (HSTS) enabled. The page currently returns HTTP 200 and presents the title “Mi tarjeta | Correos Prepago”, suggesting an attempt to lure victims with a prepaid‑card theme.

Technical profiling reveals the use of Firebase as a backend platform, together with Google Tag Manager, Google Analytics, Facebook Pixel, Cookiebot, and HTTP/3. These components are commonly observed in phishing kits that harvest credentials and track visitor activity. Reputation services assign a Gridinsoft trust score of 0 out of 100, and the domain appears on three public phishing blocklists (PhishDestroy, Phishunt, PhishingDB). VirusTotal reports that 9 of 95 scanned security vendors flag the domain as malicious, reinforcing the suspicion of active abuse.

The primary threat category is identified as a shipping‑related generic phishing campaign. While the exact content of the landing page has not been publicly disclosed, the combination of a convincing title, the presence of tracking and analytics scripts, and the low trust scores strongly indicate a credential‑harvesting operation aimed at users expecting a prepaid mail service. Defenders should prioritize blocking the domain at network perimeter devices, updating DNS blocklists, and monitoring outbound connections to the associated Fastly IP range. Continuous re‑evaluation is advised, as any changes to the site’s infrastructure or additional detections could alter the risk posture.

VirusTotal
VirusTotal
5 det.
URLQuery
यूआरएलक्वेरी
4 threat alerts
URLScan
यूआरएलस्कैन
TLS प्रमाणपत्र
समाप्त या असत्यापित -99d
आयु
6 mo
देखी गई स्थिति
असत्यापित
PhishDestroy
विनाश सूची
सूचीबद्ध
Reports Sent
1
डेटा कवरेज VirusTotal 5 / 91 यूआरएलक्वेरी 4 threat-system alerts फ़िशस्टैट्स जाँच नहीं की गई ओटीएक्स no community references सीएफ रडार scan completed URLScan capture संग्रहित रिपोर्ट URLScan verdict विश्लेषण पूरा हुआ डीएनएस ब्लॉक जाँच नहीं की गई TLS समाप्त या असत्यापित कौन है 6 mo old स्क्रीनशॉट 3 captures · 3 sources चेन पुनर्निर्देशित करें जांच नहीं की गई
नेटवर्क सुरक्षा इंटेलिजेंस
Threat Detection Systems 4 alerts
Detection System Indicator Verdict Alert
ओपनफ़िश correosprepago.bnext.es phishing Phishing - Correos
DNS4EU correosprepago.bnext.es malicious Sinkholed
DNS0 Zero correosprepago.bnext.es malicious Sinkholed
ओपनफ़िश correosprepago.bnext.es/ phishing Phishing - Correos

धमकी प्रतिक्रिया पाइपलाइन

खोज
Checks
Reports
उपलब्धता
14/15
Sent Report Recorded
Stored sent-report record for registrar Google LLC, hosting provider, 1 abuse contact
network-abuse@google.com
04/01/2026

सार्वजनिक ब्लॉकलिस्ट स्थिति

सहेजा गया कैप्चर

डोमेन इंटेलिजेंस

डोमेन
URLScan Verdict विश्लेषण पूरा हुआ score 0 report ↗
सर्वर / ASN Kestrel · AS54113 FASTLY, US
IP Context Fastly shared edge origin IP hidden एज-आईपी प्रतिष्ठा इस डोमेन के लिए जिम्मेदार नहीं है।
Registrar (base domain) Google Domains US(US)
दुरुपयोग संपर्कnetwork-abuse@google.com
IP पता 2620:0:890::100 CDN
भौगोलिक स्थानUS Mountain View, US
नेटवर्कAS54113 · Fastly, Inc.
रिवर्स IPviewdns.info → rapiddns.io →
मूल आईपी सीडीएन प्रॉक्सी के पीछे छिपा हुआ है। किनारे के पते के लिए रिवर्स-आईपी परिणामों में असंबंधित किरायेदार शामिल हैं; मूल का पता लगाने के लिए निष्क्रिय DNS या प्रमाणपत्र-पारदर्शिता डेटा की आवश्यकता होती है।
Registration (base domain)bnext.es · निर्मित 21/02/2026 (175d)
Elapsed Since First Report 17 days
हम क्या मापते हैं Raw elapsed time since the first stored abuse report. It is not a registrar response-time measurement. Latest observed status: असत्यापित.
प्रत्येक रिपोर्ट में क्या शामिल है संग्रहीत आउटगोइंग-रिपोर्ट रिकॉर्ड उस समय उपलब्ध साक्ष्य का संदर्भ दे सकते हैं, जैसे विक्रेता के फैसले, पंजीकरण डेटा, होस्टिंग विवरण, वर्गीकरण, या स्क्रीनशॉट। यह पृष्ठ किसी प्राप्तकर्ता द्वारा वितरित सटीक पेलोड, रसीद, पावती या कार्रवाई का अनुमान नहीं लगाता है।
तकनीकी विवरणडीएनएस, एसएसएल एसएएन, टाइमस्टैम्प
पहली बार पता चला26/02/2026
DOM Analysisanalyzed 09/07/2026score 63/100
IoC Extractionscanned 29/07/20260 wallet · 0 Telegram IoCs
नेमसर्वरcorreosprepago.web.app
TLS Fingerprint
TLS Observationvalid from 08/02/2026scanned 15/03/2026
Favicon Hash
Case ID
पेज शीर्षक
Mi tarjeta | Correos Prepago
TLS प्रमाणपत्र
समाप्त या असत्यापित · जारीकर्ता Google Trust Services / WR3
तकनीकें · 7 identified
Firebase
PaaS

Google platform for building mobile and web applications with backend services.

HSTS
सुरक्षा

HTTP Strict Transport Security — forces browsers to use HTTPS connections only.

Google Tag Manager
Tag managers

Tag management system for deploying marketing and analytics tags.

tagmanager.google.com
Google Analytics
Analytics

Web analytics service tracking website traffic and user behavior.

marketingplatform.google.com
Facebook Pixel

Conversion-tracking pixel by Meta — logs page views and custom events to Facebook/Instagram ad accounts.

www.facebook.com
Cookiebot
HTTP/3
Miscellaneous

Third major version of HTTP protocol, built on QUIC for faster, more reliable connections.

Detected via क्लाउडफ्लेयर रडार · Wappalyzer engine
इस डोमेन की रिपोर्ट करें सबूत जमा करें और दूसरों की सुरक्षा में मदद करें

वायरसटोटल विश्लेषण

5 / 91 सुरक्षा विक्रेताओं ने इस डोमेन को चिह्नित किया
View on VT
Last analyzed Previous stored snapshot: 9 detections
ADMINUSLabs
Chong Lua Dao
Gridinsoft
PREBYTES
VIPRE

संग्रहीत साक्ष्य

Wayback Machine Snapshot
साक्ष्य समीक्षा के लिए एक ऐतिहासिक स्नैपशॉट उपलब्ध है
View Archive
साइट प्रदर्शन विश्लेषण

Google PageSpeed Insights — mobile performance audit of correosprepago.bnext.es · checked Mar 2, 2026

66
Needs Work
Performance
FCP
2.72s
First Contentful Paint
LCP
10.39s
Largest Contentful Paint
CLS
0.069
Cumulative Layout Shift
TBT
142ms
Total Blocking Time
SI
4.03s
Speed Index
Powered by Google PageSpeed Insights · Mobile strategy · Scores: 90-100 Good 50-89 Needs Work 0-49 Poor
साइट कॉन्फ़िगरेशन विश्लेषण
Stored observations are retained with their original collection time.
robots.txt Present · HTTP 200
/$ /register /*.css$ /*.js$ /*.jpg$ /*.png$ /*.webp$

साक्ष्य और बाहरी रिपोर्टें

Submitted Evidence Snapshot
Sent: Ledger records: 1 Case ID: PD-20260104-1A6183 Recipient: network-abuse@google.com
Page title stored with report: Mi tarjeta | Correos Prepago
URLScan evidence VirusTotal evidence URLQuery evidence Screenshot 44.2 KB

क्या आप इस साइट से प्रभावित हुए?

If credentials were compromised, report immediately. Do not engage with recovery scammers.

यदि आपने खाता क्रेडेंशियल, व्यक्तिगत या भुगतान जानकारी दर्ज की है, या इस डोमेन से कोई फ़ाइल डाउनलोड की है, तो तुरंत कार्रवाई करें। घटना की रिपोर्ट करने और अपनी सुरक्षा करने में आपकी सहायता के लिए नीचे संसाधन दिए गए हैं।

यूरोपोल
अपने ईयू देश के लिए आधिकारिक रिपोर्टिंग चैनल ढूंढें
National police directory
रिकवरी ठगों से सावधान रहें! अपराधी जांचकर्ता, वकील या रिकवरी एजेंट होने का नाटक करते हुए पीड़ितों से दोबारा संपर्क कर सकते हैं। अग्रिम शुल्क का भुगतान न करें या क्रेडेंशियल साझा न करें। रिकवरी धोखाधड़ी के बारे में और जानें →

अपने स्थानीय अधिकारियों को रिपोर्ट करें

आधिकारिक साइबर अपराध संपर्क, या एक शिकायत ड्राफ्ट बनाएं → प्राप्त करने के लिए अपना देश चुनें।

97-देश निर्देशिका
एआई-सहायता प्राप्त ड्राफ्ट - घटना विवरण एआई प्रदाता द्वारा संसाधित किया जाता है इसकी स्वयं समीक्षा करें और सबमिट करें

किसी भी डोमेन की जाँच करें

संग्रहीत ब्लॉकलिस्ट, WHOIS, DNS और सार्वजनिक स्कैन साक्ष्य का उपयोग करके खतरे का विश्लेषण

अभी स्कैन करें

फ़िशिंग की रिपोर्ट करें

संदिग्ध डोमेन हमारे थ्रेट डेटाबेस में जमा करें — समुदाय की सुरक्षा करें

रिपोर्ट करें

सीधा खतरा फीड

हाल की फ़िशिंग रिपोर्टें और उपलब्धता में परिवर्तन देखे गए

निगरानी करें

जानकारी में रहें, सुरक्षित रहें

लाइव खतरों की निगरानी करें या यदि आपको लगता है कि यह एक गलत सकारात्मक है तो इस लिस्टिंग को चुनौती दें।

सीधा खतरा फीड इस लिस्टिंग के खिलाफ अपील करें
HTML · IFRAME

इस रिपोर्ट को एम्बेड करें

इस थ्रेट इंटेलिजेंस को अपनी वेबसाइट या ब्लॉग पर साझा करें।

embed.html
<iframe
  src="https://phishdestroy.io/hi/embed/domain/correosprepago.bnext.es"
  title="PhishDestroy threat report for correosprepago.bnext.es"
  width="100%" height="320"
  loading="lazy"
  referrerpolicy="no-referrer"
  sandbox="allow-same-origin allow-popups allow-popups-to-escape-sandbox"
  style="border:0;border-radius:12px;max-width:100%"
></iframe>