exho[.]pro
exho.pro की फ़िशिंग और सुरक्षा जाँच
“EXHO | Open the world of luck and rewards!”
exho.pro — अंतिम ज्ञात सक्रिय (HTTP 200). ब्रांड प्रतिरूपण: Foundation; घोटाले का प्रकार: Brand Impersonation. साक्ष्य सारांश: VirusTotal 4/91 (ADMINUSLabs, alphaMountain.ai, Fortinet, Gridinsoft); PhishDestroy score 72/100. रजिस्ट्रार: REGRU-RU.
मूल फॉरेंसिक रिकॉर्ड सुरक्षित रखने के लिए नीचे का विस्तृत PhishDestroy AI विश्लेषण अंग्रेज़ी में रखा गया है।
The domain exho.pro was registered on 24 January 2025 through the REGRU‑RU registrar. DNS resolution points to the IP address 104.21.80.1, which belongs to AS13335 operated by Cloudflare, Inc., and is geolocated in the United States. The web server returns HTTP 200 and presents the page title “EXHO | Open the world of luck and rewards!”. No TLS certificate is presented, meaning the site is served over plain HTTP. The domain is listed on a single security blocklist and has been flagged by the PhishDestroy service.
Analysis identifies this site as a brand‑impersonation campaign targeting the foundation brand, as indicated in the intelligence that the domain “impersonates: foundation”. The combination of a high‑risk classification, a Gridinsoft trust score of 0 / 100, and three out of ninety‑five VirusTotal scanners raising detections reinforces the malicious intent. The absence of an SSL certificate suggests that any credential or personal data entered by a victim would be transmitted unencrypted, a common trait of credential‑harvesting operations. Use of Cloudflare’s CDN masks the origin server, but the single resolved IP confirms a centralized hosting point.
Defenders should add exho.pro to network and email blocklists, enforce DNS sinkholing for the domain, and monitor outbound connections to 104.21.80.1. Organizations that employ the foundation brand should issue user awareness alerts highlighting that any unsolicited communication referencing “EXHO” or offering “luck and rewards” is not affiliated with the legitimate brand. Continuous scanning of the IP address and periodic re‑evaluation of VirusTotal and other reputation feeds are recommended to capture any changes in the threat landscape.
धमकी प्रतिक्रिया पाइपलाइन
सार्वजनिक ब्लॉकलिस्ट स्थिति
सहेजा गया कैप्चर
डोमेन इंटेलिजेंस
तकनीकी विवरणडीएनएस, एसएसएल एसएएन, टाइमस्टैम्प
ICANN OVERSIGHT
प्रत्यायन और आरएए संदर्भ
प्रत्यायन और आरएए संदर्भ
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
वायरसटोटल विश्लेषण
संग्रहीत साक्ष्य
साक्ष्य और बाहरी रिपोर्टें
क्या आप इस साइट से प्रभावित हुए?
यदि आपने खाता क्रेडेंशियल, व्यक्तिगत या भुगतान जानकारी दर्ज की है, या इस डोमेन से कोई फ़ाइल डाउनलोड की है, तो तुरंत कार्रवाई करें। घटना की रिपोर्ट करने और अपनी सुरक्षा करने में आपकी सहायता के लिए नीचे संसाधन दिए गए हैं।
अपने स्थानीय अधिकारियों को रिपोर्ट करें
आधिकारिक साइबर अपराध संपर्क, या एक शिकायत ड्राफ्ट बनाएं → प्राप्त करने के लिए अपना देश चुनें।
किसी भी डोमेन की जाँच करें
संग्रहीत ब्लॉकलिस्ट, WHOIS, DNS और सार्वजनिक स्कैन साक्ष्य का उपयोग करके खतरे का विश्लेषण
अभी स्कैन करेंफ़िशिंग की रिपोर्ट करें
संदिग्ध डोमेन हमारे थ्रेट डेटाबेस में जमा करें — समुदाय की सुरक्षा करें
रिपोर्ट करेंसीधा खतरा फीड
हाल की फ़िशिंग रिपोर्टें और उपलब्धता में परिवर्तन देखे गए
निगरानी करेंजानकारी में रहें, सुरक्षित रहें
लाइव खतरों की निगरानी करें या यदि आपको लगता है कि यह एक गलत सकारात्मक है तो इस लिस्टिंग को चुनौती दें।