सुरक्षा रिपोर्ट पर जाएँ
⚠️
इस डोमेन को दुर्भावनापूर्ण के रूप में चिह्नित किया गया है।
सुरक्षा इंजन एक पहचान की रिपोर्ट कर रहे हैं: 16। अत्यधिक सावधानी बरतें - क्रेडेंशियल या व्यक्तिगत जानकारी दर्ज न करें।
डोमेन सुरक्षा और ख़तरे की आसूचना

favveda[.]cfd

“Messenger”

धमकी भरा फैसला गंभीर 100/100 साक्ष्य स्कोर
उपलब्धता ढका हुआ · पहुंच योग्य क्लोकिंग जांच के माध्यम से पहुंच योग्यता देखी गई
वायरस का कुल पता लगाना: 16/91 Spamhaus DBL: DBL_PHISH URLQuery threat systems: 4 alerts घोटाले का प्रकार: Credential Phishing अंतिम ज्ञात सक्रिय
OTX: 2 refs 28/06/2026 1 Report Sent CDN

संग्रहीत पहचान

क्लोकिंग चेतावनी

क्लोकिंग प्रकार
content_divergence
क्लोकिंग स्कोर
1/6

साक्ष्य सारांश

आलोचनात्मक
Evidence score
100/100

This domain, favveda.cfd, is identified as a generic phishing site designed to impersonate the Messenger platform. Analysis indicates it functions as a fake login page, likely harvesting user credentials through deceptive input forms. No direct evidence of a crypto drainer kit or wallet interception scripts has been observed, but the infrastructure aligns with credential theft campaigns targeting social media and messaging services. The use of the 'Messenger' page title suggests an attempt to mimic the legitimate service, increasing the likelihood of successful deception among unsuspecting users. Infrastructure analysis reveals multiple technical indicators of compromise. The domain resolves to the IP address 188.114.97.3, a host that has been associated with other phishing operations in recent threat intelligence reports. It was registered on June 25, 2026, through NICENIC INTERNATIONAL GROUP CO., LIMITED, a registrar frequently utilized by threat actors for its lenient registration policies. The SSL certificate is issued by Google Trust Services, which, while providing encryption, does not validate the legitimacy of the site’s content. VirusTotal reports 16 out of 95 security vendors flagging the domain as malicious, a detection rate that confirms its classification as a high-confidence phishing threat. Google Safe Browsing (GSB) currently lists the domain as unsafe, and it appears on multiple blocklists, including those maintained by anti-phishing and threat intelligence communities. The domain remains active and poses an elevated risk to users. Immediate response actions include blacklisting the domain across enterprise and consumer security tools, as well as notifying the hosting provider to initiate takedown procedures. Despite these measures, residual risk persists due to the domain’s recent registration and the potential for rapid redeployment under a new name. Users are advised to avoid interacting with the site, verify the authenticity of any login page by checking the URL and SSL certificate details, and enable multi-factor authentication on all accounts to mitigate the impact of credential theft. Organizations should monitor for indicators of compromise, such as unusual login attempts or unauthorized access originating from this domain.

भेजे गए प्रमाण का स्नैपशॉट

भेजा गया
लेज़र रिकॉर्ड
1
केस आईडी
PD-20260628-0303BC
PDF दस्तावेज़
PDF प्रमाण
प्रमाण का पूरा पाठ
Registrar: NICENIC International Group Co., Limited (Hong Kong (China))
Policy Violations: “Services may be used only for lawful purposes… fraud, abuse and illegal activity prohibited. Violations may result in immediate suspension.” + dedicated abuse handling and takedown
Applicable Laws: Crimes Ordinance Cap.200 (Fraud), Theft Ordinance Cap.210 §16A (fraud by deception), Personal Data (Privacy) Ordinance Cap.486
VirusTotal
VirusTotal
16 det.
URLQuery
यूआरएलक्वेरी
4 threat alerts
OTX references
DNS Security
5/14
सीएफ रडार
दुर्भावनापूर्ण
TLS प्रमाणपत्र
Google Trust Services
आयु
2 mo New
देखी गई स्थिति
ढका हुआ · पहुंच योग्य HTTP 502
PhishDestroy
विनाश सूची
सूचीबद्ध
Reports Sent
1

Data Coverage

VirusTotal 16 / 91 यूआरएलक्वेरी 4 threat-system alerts फ़िशस्टैट्स जाँच नहीं की गई ओटीएक्स 2 community references सीएफ रडार provider verdict: malicious URLScan capture संग्रहित रिपोर्ट URLScan verdict निष्कर्ष उपलब्ध नहीं डीएनएस ब्लॉक 5/14 TLS valid certificate, 86d कौन है 2 mo old स्क्रीनशॉट 3 captures · 3 sources चेन पुनर्निर्देशित करें जांच नहीं की गई
नेटवर्क सुरक्षा इंटेलिजेंसRegistrar context
DNS Provider Blocks 5 / 14
Cloudflare Family Cloudflare Security Controld Adblock Controld Family Controld Malware
Threat Detection Systems 4 alerts
Detection System Indicator Verdict Alert
Cloudflare DNS favveda.cfd malicious Sinkholed
OpenDNS favveda.cfd phishing Phishing Block
DNS4EU favveda.cfd malicious Sinkholed
Hagezi Threat Feed favveda.cfd malicious Sinkholed
CF Cloudflare Radar Verdict दुर्भावनापूर्ण
Phishing
Registrar context NiceNIC
Stored registration data identifies NICENIC INTERNATIONAL GROUP CO., LIMITED (IANA 3765) as the registrar. PhishDestroy maintains separate NiceNIC abuse-report research; registrar association is contextual and is not an independent detection for this domain.
NiceNIC Verdict Full Investigation

धमकी प्रतिक्रिया पाइपलाइन

खोज
Checks
Reports
उपलब्धता
13/14

ब्लॉकलिस्ट कवरेज

10 निगरानी वाले बाहरी स्रोत · संग्रहीत स्नैपशॉट 11/08/2026

10 निगरानी वाले बाहरी स्रोत कोई मिलान नहीं

सहेजा गया कैप्चर

पेज शीर्षक
Messenger
TLS प्रमाणपत्र
Valid transport encryption · जारीकर्ता Google Trust Services · valid for 86 days

डोमेन इंटेलिजेंस

डोमेन
सर्वर / ASN cloudflare · AS13335 CLOUDFLARENET - Cloudflare, Inc., US
IP Context Cloudflare shared edge origin IP hidden एज-आईपी प्रतिष्ठा इस डोमेन के लिए जिम्मेदार नहीं है।
रजिस्ट्रार NiceNIC RU(RU) PhishDestroy Investigation
दुरुपयोग संपर्कabuse@nicenic.net
IP पता 172.67.181.178 CDN
भौगोलिक स्थानUS San Francisco, US
नेटवर्कAS13335 · Cloudflare, Inc.
रिवर्स IPviewdns.info → rapiddns.io →
मूल आईपी सीडीएन प्रॉक्सी के पीछे छिपा हुआ है। किनारे के पते के लिए रिवर्स-आईपी परिणामों में असंबंधित किरायेदार शामिल हैं; मूल का पता लगाने के लिए निष्क्रिय DNS या प्रमाणपत्र-पारदर्शिता डेटा की आवश्यकता होती है।
पंजीकरणनिर्मित 25/06/2026 (47d · New) Expires 25/06/2027
HTTP स्थिति502 Error
Elapsed Since First Report 11 days
हम क्या मापते हैं Raw elapsed time since the first stored abuse report. It is not a registrar response-time measurement. Latest observed status: ढका हुआ · पहुंच योग्य.
प्रत्येक रिपोर्ट में क्या शामिल है संग्रहीत आउटगोइंग-रिपोर्ट रिकॉर्ड उस समय उपलब्ध साक्ष्य का संदर्भ दे सकते हैं, जैसे विक्रेता के फैसले, पंजीकरण डेटा, होस्टिंग विवरण, वर्गीकरण, या स्क्रीनशॉट। यह पृष्ठ किसी प्राप्तकर्ता द्वारा वितरित सटीक पेलोड, रसीद, पावती या कार्रवाई का अनुमान नहीं लगाता है।
तकनीकी विवरणDNS, TLS नाम और समय-मुद्राएँ
पहली बार पता चला28/06/2026
DOM Analysisanalyzed 09/07/2026DOM analysis score 100/100
Submitted URLhttps://favveda.cfd/
नेमसर्वरathena.ns.cloudflare.comfelipe.ns.cloudflare.com
TLS अवलोकन09/07/2026 को स्कैन किया गया
SHORTDOT ज़ोन · सार्वजनिक साक्ष्य .cfd

ShortDot zone evidence

The linked repository preserves daily zone observations across seven ShortDot-operated TLDs, including registration volume and abuse-related indicators. This registry context is supporting background and is not an independent detection for the domain in this report.

ShortDot SA · Luxembourg 7 ज़ोन · पूरे ज़ोन के साक्ष्य प्रतिदिन अपडेट किए जाते हैं ShortDot साक्ष्य रिपॉज़िटरी खोलें
ICANN OVERSIGHT

प्रत्यायन और आरएए संदर्भ

Registrar accreditation and DNS abuse obligations

For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.

Accreditation is a contract, not a safety certification.

RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.

मान्यता एक अनुबंध है, सुरक्षा की मुहर नहीं। ICANN शुल्क सत्यापित करें RAA §3.18 पढ़ें PHISHDESTROY INVESTIGATIONICANN funding, contracts, and DNS abuse oversight
Accountability draft कुछ भी अपने आप नहीं भेजा जाता।

तकनीकें

3 उच्च-विश्वसनीयता वाली तकनीकें पहचानी गईं

Vue.js Cloudflare HTTP/3
Cloudflare Radar
इस डोमेन की रिपोर्ट करें सबूत जमा करें और दूसरों की सुरक्षा में मदद करें

वायरसटोटल विश्लेषण

16 / 91 सुरक्षा विक्रेताओं ने इस डोमेन को चिह्नित किया
View on VT
Last analyzed
alphaMountain.ai
BitDefender
CRDF
साइरेडार
ईएसईटी
Emsisoft
Fortinet
G-Data
Gridinsoft
कास्परस्की
LevelBlue
Lionic
नेटक्राफ्ट
SOCRadar
सोफोस
वेबरूट
साइट प्रदर्शन विश्लेषण

Google PageSpeed Insights — mobile performance audit of favveda.cfd · checked Jun 28, 2026

100
Good
Performance
FCP
0.76s
First Contentful Paint
LCP
0.76s
Largest Contentful Paint
CLS
0
Cumulative Layout Shift
TBT
0ms
Total Blocking Time
SI
1.06s
Speed Index
Powered by Google PageSpeed Insights · Mobile strategy · Scores: 90-100 Good 50-89 Needs Work 0-49 Poor

क्या आप इस साइट से प्रभावित हुए?

If credentials were compromised, report immediately. Do not engage with recovery scammers.

यदि आपने खाता क्रेडेंशियल, व्यक्तिगत या भुगतान जानकारी दर्ज की है, या इस डोमेन से कोई फ़ाइल डाउनलोड की है, तो तुरंत कार्रवाई करें। घटना की रिपोर्ट करने और अपनी सुरक्षा करने में आपकी सहायता के लिए नीचे संसाधन दिए गए हैं।

यूरोपोल
अपने ईयू देश के लिए आधिकारिक रिपोर्टिंग चैनल ढूंढें
National police directory
रिकवरी ठगों से सावधान रहें! अपराधी जांचकर्ता, वकील या रिकवरी एजेंट होने का नाटक करते हुए पीड़ितों से दोबारा संपर्क कर सकते हैं। अग्रिम शुल्क का भुगतान न करें या क्रेडेंशियल साझा न करें। रिकवरी धोखाधड़ी के बारे में और जानें →

अपने स्थानीय अधिकारियों को रिपोर्ट करें

आधिकारिक साइबर अपराध संपर्क, या एक शिकायत ड्राफ्ट बनाएं → प्राप्त करने के लिए अपना देश चुनें।

97-देश निर्देशिका
एआई-सहायता प्राप्त ड्राफ्ट - घटना विवरण एआई प्रदाता द्वारा संसाधित किया जाता है इसकी स्वयं समीक्षा करें और सबमिट करें

किसी भी डोमेन की जाँच करें

संग्रहीत ब्लॉकलिस्ट, WHOIS, DNS और सार्वजनिक स्कैन साक्ष्य का उपयोग करके खतरे का विश्लेषण

अभी स्कैन करें

फ़िशिंग की रिपोर्ट करें

संदिग्ध डोमेन हमारे थ्रेट डेटाबेस में जमा करें — समुदाय की सुरक्षा करें

रिपोर्ट करें

सीधा खतरा फीड

हाल की फ़िशिंग रिपोर्टें और उपलब्धता में परिवर्तन देखे गए

निगरानी करें

जानकारी में रहें, सुरक्षित रहें

लाइव खतरों की निगरानी करें या यदि आपको लगता है कि यह एक गलत सकारात्मक है तो इस लिस्टिंग को चुनौती दें।

सीधा खतरा फीड इस लिस्टिंग के खिलाफ अपील करें

बाहरी उपकरण

HTML · IFRAME

इस रिपोर्ट को एम्बेड करें

इस थ्रेट इंटेलिजेंस को अपनी वेबसाइट या ब्लॉग पर साझा करें।

embed.html
<iframe
  src="https://phishdestroy.io/hi/embed/domain/favveda.cfd"
  title="PhishDestroy threat report for favveda.cfd"
  width="100%" height="320"
  loading="lazy"
  referrerpolicy="no-referrer"
  sandbox="allow-same-origin allow-popups allow-popups-to-escape-sandbox"
  style="border:0;border-radius:12px;max-width:100%"
></iframe>

एक अत्यंत सच्चा धन्यवाद-पत्र

व्यंग्यात्मक मसौदा जनरेटर

प्राप्तकर्ता
शुल्क संदर्भ

यह व्यंग्यात्मक मसौदा है। शुल्क के आंकड़े अनुमान हैं; इन्हें इस डोमेन से ठीक-ठीक जोड़ने का दावा नहीं किया जाता।