getmoss[.]co[.]com
“Getmoss Login | Moss - spend management platform | Getmoss”
साक्ष्य सारांश
This domain is flagged as a high-risk brand impersonation phishing site targeting users of the Moss spend management platform. Analysis indicates the site mimics legitimate login portals to harvest corporate credentials, posing significant financial and operational risks to organizations. The domain specifically replicates the Moss login interface, as evidenced by the page title 'Getmoss Login | Moss - spend management platform | Getmoss,' designed to deceive employees into entering sensitive authentication details. Infrastructure analysis reveals the domain getmoss.co.com was registered on February 21, 2026, and resolves to the IP address 144.31.244.50, hosted under AS213877 (U1 DIGITAL SERVICES LTD) in Germany. The domain appears on 5 security blocklists and is flagged by 18 out of 95 security vendors on VirusTotal. Additional technical indicators include an SSL certificate issued under the R12 root and prior blocking by multiple threat intelligence feeds, including PhishDestroy, Polkadot, Enkrypt, Codeesura, and PhishingDB. The domain has since been taken offline, but residual risk remains for systems that may have cached DNS records or stored malicious artifacts. Mitigation requires immediate action from network administrators and security teams. Block the domain getmoss.co.com and its associated IP 144.31.244.50 at the firewall and DNS resolver levels. Invalidate any cached DNS entries for this domain to prevent resolution attempts. Conduct a retrospective analysis of proxy and DNS logs for connections to 144.31.244.50 or getmoss.co.com within the last 30 days to identify compromised accounts. Reset credentials for any users who accessed the domain, particularly those with financial or administrative privileges. Deploy indicators of compromise (IOCs) across endpoint detection and response (EDR) systems to detect and prevent future access. Educate employees on recognizing brand impersonation tactics, emphasizing verification of domain authenticity before entering login credentials.
Data Coverage
धमकी प्रतिक्रिया पाइपलाइन
ब्लॉकलिस्ट कवरेज
10 निगरानी वाले बाहरी स्रोत · संग्रहीत स्नैपशॉट 11/08/2026
7 निगरानी वाले बाहरी स्रोत कोई मिलान नहीं
फॉरेंसिक इंटेलिजेंस
वायरसटोटल विश्लेषण
क्या आप इस साइट से प्रभावित हुए?
यदि आपने खाता क्रेडेंशियल, व्यक्तिगत या भुगतान जानकारी दर्ज की है, या इस डोमेन से कोई फ़ाइल डाउनलोड की है, तो तुरंत कार्रवाई करें। घटना की रिपोर्ट करने और अपनी सुरक्षा करने में आपकी सहायता के लिए नीचे संसाधन दिए गए हैं।
अपने स्थानीय अधिकारियों को रिपोर्ट करें
आधिकारिक साइबर अपराध संपर्क, या एक शिकायत ड्राफ्ट बनाएं → प्राप्त करने के लिए अपना देश चुनें।
किसी भी डोमेन की जाँच करें
संग्रहीत ब्लॉकलिस्ट, WHOIS, DNS और सार्वजनिक स्कैन साक्ष्य का उपयोग करके खतरे का विश्लेषण
अभी स्कैन करेंफ़िशिंग की रिपोर्ट करें
संदिग्ध डोमेन हमारे थ्रेट डेटाबेस में जमा करें — समुदाय की सुरक्षा करें
रिपोर्ट करेंसीधा खतरा फीड
हाल की फ़िशिंग रिपोर्टें और उपलब्धता में परिवर्तन देखे गए
निगरानी करेंजानकारी में रहें, सुरक्षित रहें
लाइव खतरों की निगरानी करें या यदि आपको लगता है कि यह एक गलत सकारात्मक है तो इस लिस्टिंग को चुनौती दें।