सुरक्षा रिपोर्ट पर जाएँ
⚠️
इस डोमेन को दुर्भावनापूर्ण के रूप में चिह्नित किया गया है।
सुरक्षा इंजन एक पहचान की रिपोर्ट कर रहे हैं: 4। अत्यधिक सावधानी बरतें - क्रेडेंशियल या व्यक्तिगत जानकारी दर्ज न करें।
ABUSE NOTICE · 7D+ OPEN Outgoing abuse reports are recorded; the latest stored availability evidence still shows the domain reachable.
Notification and current-status evidence

The sent-report ledger records the first outgoing report at . A report was sent to the recorded registrar; contact details remain in Domain Intelligence. The latest stored availability evidence still shows the domain reachable; 4 months has elapsed since the first outgoing report.

ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.

Elapsed since first report
4 months
Reports sent
1
Current status
HTTP 200 at latest stored check
डोमेन सुरक्षा और ख़तरे की आसूचना

ga[.]eng[.]br

“MEGAWIN288 | Bocoran RTP Live Gacor”

धमकी भरा फैसला गंभीर 85/100 साक्ष्य स्कोर
उपलब्धता ढका हुआ · पहुंच योग्य क्लोकिंग जांच के माध्यम से पहुंच योग्यता देखी गई
वायरस का कुल पता लगाना: 4/94 URLQuery threat systems: 1 alert घोटाले का प्रकार: Crypto Gambling अंतिम ज्ञात सक्रिय
31/03/2026 1 Report Sent

संग्रहीत पहचान

क्लोकिंग चेतावनी

क्लोकिंग प्रकार
content_divergence
क्लोकिंग स्कोर
1/6
स्कैनर को दिखाया गया शीर्षकGA Engenharia Elétrica
आगंतुक को दिखाया गया शीर्षकMEGAWIN288 | Bocoran RTP Live Gacor

साक्ष्य सारांश

आलोचनात्मक
Evidence score
85/100

This domain, ga.eng.br, is actively engaged in credential theft and fraudulent gambling operations, specifically targeting users seeking real-time return-to-player (RTP) statistics under the guise of "MEGAWIN288 | Bocoran RTP Live Gacor." Analysis indicates the site is designed to harvest login credentials, payment details, or personal information from victims under the pretense of providing exclusive gambling insights. No direct evidence of a crypto drainer kit was observed, but the combination of credential theft and gambling fraud suggests a multi-stage monetization strategy, likely involving unauthorized access to user accounts or financial instruments. Infrastructure analysis reveals the domain resolves to IP address 162.241.2.208 and was registered on March 31, 2026, an anomalous creation date that may indicate domain spoofing or a typo-squatting attempt. The domain is flagged by 12 out of 95 security vendors on VirusTotal, with a Gridinsoft trust score of 0/100. It appears on one security blocklist and is currently blocked by PhishDestroy. The site employs a Let's Encrypt SSL certificate, which, while providing encryption, is commonly abused by malicious actors due to its low-barrier issuance process. Detected technologies include Shopify, Apache HTTP Server, AMP, Slick, jQuery, and BugSnag, suggesting a templated or kit-based deployment rather than a custom-built infrastructure. The domain remains active and poses an elevated risk to users, particularly those in gambling or cryptocurrency communities. Immediate response actions should include blacklisting the domain and IP across security gateways, notifying the registrar of abusive activity, and alerting financial institutions to monitor for fraudulent transactions linked to this campaign. Users are advised to avoid interacting with the domain, reset credentials for any accounts accessed via the site, and verify the legitimacy of any gambling or financial platforms through official channels. The anomalous creation date and low detection rate among security vendors underscore the need for heightened vigilance, as this campaign may evade traditional detection mechanisms.

भेजे गए प्रमाण का स्नैपशॉट

भेजा गया
लेज़र रिकॉर्ड
1
केस आईडी
PD-20260331-5777CF
कैप्चर किए गए पेज का शीर्षक
Secure access · SharePoint
PDF दस्तावेज़
PDF प्रमाण
प्रमाण का पूरा पाठ
Policy Violations:
Illegal Activities: Active phishing operation targeting victims
Fraud & Deception: Impersonation of legitimate services
Identity Theft: Collection of credentials under false pretenses
Applicable Laws (BR):
International Anti-Cybercrime Regulations
Budapest Convention on Cybercrime
Universal Fraud Prevention Laws
Phishing activities violate international cybercrime conventions and BR's domestic fraud laws.
Action Required: This evidence-backed report demonstrates clear violations requiring suspension per your policies. Continued hosting exposes your organization to regulatory scrutiny and potential legal liability.
VirusTotal
VirusTotal
4 det.
URLQuery
यूआरएलक्वेरी
1 threat alert
DNS Security
5/12
TLS प्रमाणपत्र
Let's Encrypt
आयु
4 mo
देखी गई स्थिति
ढका हुआ · पहुंच योग्य HTTP 200
PhishDestroy
विनाश सूची
सूचीबद्ध
Reports Sent
1

Data Coverage

VirusTotal 4 / 94 यूआरएलक्वेरी 1 threat-system alert फ़िशस्टैट्स checked — no match recorded ओटीएक्स no community references सीएफ रडार scan completed URLScan capture संग्रहित रिपोर्ट URLScan verdict विश्लेषण पूरा हुआ डीएनएस ब्लॉक 5/12 TLS valid certificate, 59d कौन है 4 mo old स्क्रीनशॉट 3 captures · 3 sources चेन पुनर्निर्देशित करें जांच नहीं की गई
नेटवर्क सुरक्षा इंटेलिजेंस
DNS Provider Blocks 5 / 12
Adguard Default Adguard Family Controld Adblock Controld Family Controld Malware
Threat Detection Systems 1 alert
Detection System Indicator Verdict Alert
Hagezi Threat Feed ga.eng.br malicious Sinkholed

धमकी प्रतिक्रिया पाइपलाइन

खोज
Checks
Reports
उपलब्धता
11/12

ब्लॉकलिस्ट कवरेज

10 निगरानी वाले बाहरी स्रोत · संग्रहीत स्नैपशॉट 12/08/2026

10 निगरानी वाले बाहरी स्रोत कोई मिलान नहीं

पहचान समयरेखा

  1. VirusTotal

    4 → 12

सहेजा गया कैप्चर

डोमेन इंटेलिजेंस

डोमेन
URLScan Verdict विश्लेषण पूरा हुआ score 0 report ↗
सर्वर / ASN Apache · AS31898 Oracle Corporation
IP प्रतिष्ठा IP abuse confidence 0/100 0 reports checked 14/07/2026
रजिस्ट्रार अज्ञात BR(BR)
दुरुपयोग संपर्कabuse@bluehost.com
IP पता 162.241.2.208 BR
भौगोलिक स्थानBR Vinhedo, BR
नेटवर्कAS31898 · Unified Layer
रिवर्स IPviewdns.info → rapiddns.io →
पंजीकरणनिर्मित 31/03/2026 (134d) Expires 03/03/2027
Elapsed Since First Report 14h
हम क्या मापते हैं Raw elapsed time since the first stored abuse report. It is not a registrar response-time measurement. Latest observed status: ढका हुआ · पहुंच योग्य.
प्रत्येक रिपोर्ट में क्या शामिल है संग्रहीत आउटगोइंग-रिपोर्ट रिकॉर्ड उस समय उपलब्ध साक्ष्य का संदर्भ दे सकते हैं, जैसे विक्रेता के फैसले, पंजीकरण डेटा, होस्टिंग विवरण, वर्गीकरण, या स्क्रीनशॉट। यह पृष्ठ किसी प्राप्तकर्ता द्वारा वितरित सटीक पेलोड, रसीद, पावती या कार्रवाई का अनुमान नहीं लगाता है।
HTTP स्थिति200
तकनीकी विवरणDNS, TLS नाम और समय-मुद्राएँ
पहली बार पता चला31/03/2026
Submitted URLhttp://ga.eng.br/RisingAboveMinistry/rhondashort.html
नेमसर्वरns516.hostgator.com.brns517.hostgator.com.br
TLS फिंगरप्रिंट
TLS अवलोकन26/03/2026 से मान्य23/04/2026 को स्कैन किया गया
TLS सब्जेक्ट वैकल्पिक नामautodiscover.ga.eng.brcpanel.ga.eng.brcpcalendars.ga.eng.brcpcontacts.ga.eng.brmail.ga.eng.brwebdisk.ga.eng.brwebmail.ga.eng.brwww.ga.eng.br
Favicon Hash
पेज शीर्षक
MEGAWIN288 | Bocoran RTP Live Gacor
TLS प्रमाणपत्र
Valid transport encryption · जारीकर्ता Let's Encrypt · valid for 59 days
Casino / Gambling License Verification
Unverified gambling license
This domain markets casino/gambling services. Scam casinos routinely display fake Curaçao, MGA, or Kahnawake license badges that don’t exist in the real registries. Always verify the license number against the official regulator database before depositing. If the site shows a seal but no clickable registry link — or the linked registry page doesn’t exist — treat it as fraudulent.
Curaçao eGaming (official) Malta Gaming Authority UK Gambling Commission PA Gaming Control Kahnawake Gaming Gibraltar Gambling
इस डोमेन की रिपोर्ट करें सबूत जमा करें और दूसरों की सुरक्षा में मदद करें

वायरसटोटल विश्लेषण

4 / 94 सुरक्षा विक्रेताओं ने इस डोमेन को चिह्नित किया
View on VT
Last analyzed
alphaMountain.ai
CRDF
Gridinsoft
SOCRadar
साइट प्रदर्शन विश्लेषण

Google PageSpeed Insights — mobile performance audit of ga.eng.br · checked Jun 26, 2026

68
Needs Work
Performance
FCP
3.38s
First Contentful Paint
LCP
3.68s
Largest Contentful Paint
CLS
0.201
Cumulative Layout Shift
TBT
0ms
Total Blocking Time
SI
6.03s
Speed Index
Powered by Google PageSpeed Insights · Mobile strategy · Scores: 90-100 Good 50-89 Needs Work 0-49 Poor

क्या आप इस साइट से प्रभावित हुए?

If credentials were compromised, report immediately. Do not engage with recovery scammers.

यदि आपने खाता क्रेडेंशियल, व्यक्तिगत या भुगतान जानकारी दर्ज की है, या इस डोमेन से कोई फ़ाइल डाउनलोड की है, तो तुरंत कार्रवाई करें। घटना की रिपोर्ट करने और अपनी सुरक्षा करने में आपकी सहायता के लिए नीचे संसाधन दिए गए हैं।

यूरोपोल
अपने ईयू देश के लिए आधिकारिक रिपोर्टिंग चैनल ढूंढें
National police directory
रिकवरी ठगों से सावधान रहें! अपराधी जांचकर्ता, वकील या रिकवरी एजेंट होने का नाटक करते हुए पीड़ितों से दोबारा संपर्क कर सकते हैं। अग्रिम शुल्क का भुगतान न करें या क्रेडेंशियल साझा न करें। रिकवरी धोखाधड़ी के बारे में और जानें →

अपने स्थानीय अधिकारियों को रिपोर्ट करें

आधिकारिक साइबर अपराध संपर्क, या एक शिकायत ड्राफ्ट बनाएं → प्राप्त करने के लिए अपना देश चुनें।

97-देश निर्देशिका
एआई-सहायता प्राप्त ड्राफ्ट - घटना विवरण एआई प्रदाता द्वारा संसाधित किया जाता है इसकी स्वयं समीक्षा करें और सबमिट करें

किसी भी डोमेन की जाँच करें

संग्रहीत ब्लॉकलिस्ट, WHOIS, DNS और सार्वजनिक स्कैन साक्ष्य का उपयोग करके खतरे का विश्लेषण

अभी स्कैन करें

फ़िशिंग की रिपोर्ट करें

संदिग्ध डोमेन हमारे थ्रेट डेटाबेस में जमा करें — समुदाय की सुरक्षा करें

रिपोर्ट करें

सीधा खतरा फीड

हाल की फ़िशिंग रिपोर्टें और उपलब्धता में परिवर्तन देखे गए

निगरानी करें

जानकारी में रहें, सुरक्षित रहें

लाइव खतरों की निगरानी करें या यदि आपको लगता है कि यह एक गलत सकारात्मक है तो इस लिस्टिंग को चुनौती दें।

सीधा खतरा फीड इस लिस्टिंग के खिलाफ अपील करें

बाहरी उपकरण

HTML · IFRAME

इस रिपोर्ट को एम्बेड करें

इस थ्रेट इंटेलिजेंस को अपनी वेबसाइट या ब्लॉग पर साझा करें।

embed.html
<iframe
  src="https://phishdestroy.io/hi/embed/domain/ga.eng.br"
  title="PhishDestroy threat report for ga.eng.br"
  width="100%" height="320"
  loading="lazy"
  referrerpolicy="no-referrer"
  sandbox="allow-same-origin allow-popups allow-popups-to-escape-sandbox"
  style="border:0;border-radius:12px;max-width:100%"
></iframe>