सुरक्षा रिपोर्ट पर जाएँ
⚠️
इस डोमेन को दुर्भावनापूर्ण के रूप में चिह्नित किया गया है।
सुरक्षा इंजन एक पहचान की रिपोर्ट कर रहे हैं: 9। अत्यधिक सावधानी बरतें - क्रेडेंशियल या व्यक्तिगत जानकारी दर्ज न करें।
डोमेन सुरक्षा और ख़तरे की आसूचना

expensestatus[.]com

“404 - Quick Tip | Cofense”

धमकी भरा फैसला गंभीर 100/100 साक्ष्य स्कोर
उपलब्धता ढका हुआ · पहुंच योग्य क्लोकिंग जांच के माध्यम से पहुंच योग्यता देखी गई
वायरस का कुल पता लगाना: 9/91 घोटाले का प्रकार: Generic Phishing अंतिम ज्ञात सक्रिय
OTX: 50 refs 08/07/2026
रिपोर्ट सारांश

expensestatus.com — ढका हुआ · पहुंच योग्य. घोटाले का प्रकार: Generic Phishing. साक्ष्य सारांश: VirusTotal 9/91 (ADMINUSLabs, alphaMountain.ai, Chong Lua Dao, Forcepoint ThreatSeeker, Fortinet); cloaking observed; PhishDestroy score 100/100. रजिस्ट्रार: MarkMonitor.

मूल फॉरेंसिक रिकॉर्ड सुरक्षित रखने के लिए नीचे का विस्तृत PhishDestroy AI विश्लेषण अंग्रेज़ी में रखा गया है।

साक्ष्य सारांश
आलोचनात्मक
संदर्भ
73121E91
स्कोर
100/100

This domain operates as a credential harvesting platform designed to mimic legitimate corporate expense management systems. Analysis indicates expensestatus.com presents fraudulent login interfaces that closely resemble enterprise expense reporting tools, with the primary objective of capturing employee usernames, passwords, and potentially multi-factor authentication codes. The site employs convincing corporate branding elements and expense-related terminology to deceive victims into submitting sensitive authentication details. Infrastructure analysis reveals multiple high-confidence indicators of malicious activity. The domain was registered on June 12, 2017 through MarkMonitor, Inc., an unusual registrar choice for typical phishing operations that often use budget providers. Security telemetry shows 8 out of 95 security vendors on VirusTotal flag this domain as malicious, with detections spanning phishing, credential theft, and corporate espionage categories. The domain appears on two specialized security blocklists (PhishingDB and BLP-Malware) and resolves to IP address 52.204.246.179, hosted on infrastructure commonly associated with cloud-based phishing campaigns. The Let's Encrypt SSL certificate provides HTTPS encryption, creating a false sense of security while facilitating the credential interception process. Organizations and individuals who have interacted with expensestatus.com should immediately initiate incident response procedures. All credentials potentially exposed through this domain must be considered compromised and rotated across all systems where identical or similar passwords may have been reused. Security teams should examine network logs for connections to 52.204.246.179 and review endpoint detection data for any processes that may have communicated with this IP address. Users who entered credentials should enable additional authentication factors where available and monitor accounts for unauthorized access attempts. Corporate security teams are advised to implement DNS-based blocking of this domain and its associated IP address across all enterprise systems to prevent further exposure.

VirusTotal
VirusTotal
9 det.
OTX references
DNS Security
4/14
URLScan
यूआरएलस्कैन
TLS प्रमाणपत्र
Let's Encrypt
आयु
9.2 yr
देखी गई स्थिति
ढका हुआ · पहुंच योग्य
PhishDestroy
विनाश सूची
सूचीबद्ध
डेटा कवरेज VirusTotal 9 / 91 यूआरएलक्वेरी source data unavailable फ़िशस्टैट्स जाँच नहीं की गई ओटीएक्स 50 community references सीएफ रडार scan completed URLScan capture संग्रहित रिपोर्ट URLScan verdict विश्लेषण पूरा हुआ डीएनएस ब्लॉक 4/14 TLS valid certificate, 35d कौन है 112 mo old स्क्रीनशॉट 2 captures · 2 sources चेन पुनर्निर्देशित करें जांच नहीं की गई
नेटवर्क सुरक्षा इंटेलिजेंस
DNS Provider Blocks 4 / 14
Adguard Family Controld Adblock Controld Family Controld Malware

धमकी प्रतिक्रिया पाइपलाइन

खोज
Checks
Reports
उपलब्धता
12/14

सार्वजनिक ब्लॉकलिस्ट स्थिति

सहेजा गया कैप्चर

पेज शीर्षक
404 - Quick Tip | Cofense
TLS प्रमाणपत्र
Valid transport encryption · जारीकर्ता Let's Encrypt · valid for 35 days

डोमेन इंटेलिजेंस

डोमेन
URLScan Verdict विश्लेषण पूरा हुआ score 0 report ↗
सर्वर / ASN AS14618 AMAZON-AES - Amazon.com, Inc., US
IP प्रतिष्ठा abuse score 0/100 0 reports checked 08/08/2026
रजिस्ट्रार MarkMonitor US(US)
दुरुपयोग संपर्कabusecomplaints@markmonitor.com, whoisrequest@markmonitor.com
IP पता 52.204.246.179 US
भौगोलिक स्थानUS Ashburn, US
नेटवर्कAS14618 · Amazon.com, Inc.
रिवर्स IPviewdns.info → rapiddns.io →
पंजीकरणनिर्मित 12/06/2017 Expires 12/06/2028
Cloaking Cloaking Detected Content divergence · score 2/6
unavailable: raw=proxy_error; http=0; via=http_proxy; error=HTTPConnectionPool(host='171.22.251.115', port=5645): Max retries exceeded with url: http://expensestatus.com/ (Caused b
checked 13/08/2026
Elapsed Since First Report 12h
हम क्या मापते हैं Raw elapsed time since the first stored abuse report. It is not a registrar response-time measurement. Latest observed status: ढका हुआ · पहुंच योग्य.
प्रत्येक रिपोर्ट में क्या शामिल है संग्रहीत आउटगोइंग-रिपोर्ट रिकॉर्ड उस समय उपलब्ध साक्ष्य का संदर्भ दे सकते हैं, जैसे विक्रेता के फैसले, पंजीकरण डेटा, होस्टिंग विवरण, वर्गीकरण, या स्क्रीनशॉट। यह पृष्ठ किसी प्राप्तकर्ता द्वारा वितरित सटीक पेलोड, रसीद, पावती या कार्रवाई का अनुमान नहीं लगाता है।
तकनीकी विवरणडीएनएस, एसएसएल एसएएन, टाइमस्टैम्प
पहली बार पता चला08/07/2026
DOM Analysisanalyzed 28/07/2026score 100/100
IoC Extractionscanned 29/07/20260 wallet · 0 Telegram IoCs
Submitted URLhttp://expensestatus.com/s/63BZGFSVBWSFCDX7Y9/584dd8/90eab167-7429-489f-99f6-ce86e8d0d81a
नेमसर्वरns-1104.awsdns-10.orgns-1580.awsdns-05.co.ukns-364.awsdns-45.comns-667.awsdns-19.net
TLS Fingerprint
TLS Observationvalid from 14/05/2026scanned 27/07/2026
Favicon Hash
ICANN OVERSIGHT

प्रत्यायन और आरएए संदर्भ

Registrar accreditation and DNS abuse obligations

For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.

Accreditation is a contract, not a safety certification.

RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.

मान्यता एक अनुबंध है, सुरक्षा की मुहर नहीं। ICANN शुल्क सत्यापित करें RAA §3.18 पढ़ें PHISHDESTROY INVESTIGATIONICANN funding, contracts, and DNS abuse oversight
Accountability draft कुछ भी अपने आप नहीं भेजा जाता।
तकनीकें · 1 identified
HSTS
सुरक्षा

HTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.

www.rfc-editor.org 100% विश्वास
Detected via क्लाउडफ्लेयर रडार · Wappalyzer engine
इस डोमेन की रिपोर्ट करें सबूत जमा करें और दूसरों की सुरक्षा में मदद करें

वायरसटोटल विश्लेषण

9 / 91 सुरक्षा विक्रेताओं ने इस डोमेन को चिह्नित किया
View on VT
Last analyzed
ADMINUSLabs
alphaMountain.ai
Chong Lua Dao
Forcepoint ThreatSeeker
Fortinet
Gridinsoft
SafeToOpen
SOCRadar
यूआरएलक्वेरी
साइट प्रदर्शन विश्लेषण

Google PageSpeed Insights — mobile performance audit of expensestatus.com · checked Jul 8, 2026

94
Good
Performance
FCP
0.76s
First Contentful Paint
LCP
1.8s
Largest Contentful Paint
CLS
0.142
Cumulative Layout Shift
TBT
0ms
Total Blocking Time
SI
1.02s
Speed Index
Powered by Google PageSpeed Insights · Mobile strategy · Scores: 90-100 Good 50-89 Needs Work 0-49 Poor
साइट कॉन्फ़िगरेशन विश्लेषण
Stored observations are retained with their original collection time.
robots.txt Present · HTTP 200
Valid robots.txt; no Disallow/Allow paths were extracted.

साक्ष्य और बाहरी रिपोर्टें

क्या आप इस साइट से प्रभावित हुए?

If credentials were compromised, report immediately. Do not engage with recovery scammers.

यदि आपने खाता क्रेडेंशियल, व्यक्तिगत या भुगतान जानकारी दर्ज की है, या इस डोमेन से कोई फ़ाइल डाउनलोड की है, तो तुरंत कार्रवाई करें। घटना की रिपोर्ट करने और अपनी सुरक्षा करने में आपकी सहायता के लिए नीचे संसाधन दिए गए हैं।

यूरोपोल
अपने ईयू देश के लिए आधिकारिक रिपोर्टिंग चैनल ढूंढें
National police directory
रिकवरी ठगों से सावधान रहें! अपराधी जांचकर्ता, वकील या रिकवरी एजेंट होने का नाटक करते हुए पीड़ितों से दोबारा संपर्क कर सकते हैं। अग्रिम शुल्क का भुगतान न करें या क्रेडेंशियल साझा न करें। रिकवरी धोखाधड़ी के बारे में और जानें →

अपने स्थानीय अधिकारियों को रिपोर्ट करें

आधिकारिक साइबर अपराध संपर्क, या एक शिकायत ड्राफ्ट बनाएं → प्राप्त करने के लिए अपना देश चुनें।

97-देश निर्देशिका
एआई-सहायता प्राप्त ड्राफ्ट - घटना विवरण एआई प्रदाता द्वारा संसाधित किया जाता है इसकी स्वयं समीक्षा करें और सबमिट करें

किसी भी डोमेन की जाँच करें

संग्रहीत ब्लॉकलिस्ट, WHOIS, DNS और सार्वजनिक स्कैन साक्ष्य का उपयोग करके खतरे का विश्लेषण

अभी स्कैन करें

फ़िशिंग की रिपोर्ट करें

संदिग्ध डोमेन हमारे थ्रेट डेटाबेस में जमा करें — समुदाय की सुरक्षा करें

रिपोर्ट करें

सीधा खतरा फीड

हाल की फ़िशिंग रिपोर्टें और उपलब्धता में परिवर्तन देखे गए

निगरानी करें

जानकारी में रहें, सुरक्षित रहें

लाइव खतरों की निगरानी करें या यदि आपको लगता है कि यह एक गलत सकारात्मक है तो इस लिस्टिंग को चुनौती दें।

सीधा खतरा फीड इस लिस्टिंग के खिलाफ अपील करें
HTML · IFRAME

इस रिपोर्ट को एम्बेड करें

इस थ्रेट इंटेलिजेंस को अपनी वेबसाइट या ब्लॉग पर साझा करें।

embed.html
<iframe
  src="https://phishdestroy.io/hi/embed/domain/expensestatus.com"
  title="PhishDestroy threat report for expensestatus.com"
  width="100%" height="320"
  loading="lazy"
  referrerpolicy="no-referrer"
  sandbox="allow-same-origin allow-popups allow-popups-to-escape-sandbox"
  style="border:0;border-radius:12px;max-width:100%"
></iframe>

एक अत्यंत सच्चा धन्यवाद-पत्र

व्यंग्यात्मक मसौदा जनरेटर

प्राप्तकर्ता
शुल्क संदर्भ

यह व्यंग्यात्मक मसौदा है। शुल्क के आंकड़े अनुमान हैं; इन्हें इस डोमेन से ठीक-ठीक जोड़ने का दावा नहीं किया जाता।