Notification and current-status evidence
The sent-report ledger records the first outgoing report at . A report was sent to the recorded registrar; contact details remain in Domain Intelligence. The latest stored availability evidence still shows the domain reachable; 6 months has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
ilmxs[.]com
“New API”
साक्ष्य सारांश
This domain, ilmxs.com, is identified as a credential theft operation targeting software developers and API integrators. Analysis indicates the site masquerades as a legitimate API service portal, using the page title 'New API' to lure victims into submitting authentication credentials. The threat is designed to harvest login details for subsequent unauthorized access to cloud environments, version control systems, or corporate networks, with potential secondary payload delivery for persistent compromise. Infrastructure analysis reveals multiple high-confidence indicators of malicious activity. The domain was registered on February 21, 2026, through Alibaba Cloud Computing Ltd. (HiChina), an uncommon registrar for legitimate API services. It resolves to IP address 101.201.155.42, hosted on AS37963 (Hangzhou Alibaba Advertising Co., Ltd.) in China. Security vendors have flagged ilmxs.com on VirusTotal with 21 detections out of 95 engines, while two independent blocklists (PhishDestroy and PhishingDB) have listed it as malicious. The SSL certificate, issued by DigiCert's Encryption Everywhere DV TLS CA - G2, provides minimal validation and is commonly abused in phishing infrastructure. Users who visited ilmxs.com or interacted with its content should immediately take containment actions. Reset all credentials entered on the site, particularly API keys, database passwords, and cloud service logins. Conduct a full system scan for malware using updated detection signatures, focusing on browser-based keyloggers or credential dumping tools. Review network logs for connections to 101.201.155.42 or related subdomains of ilmxs.com. Organizations should block the domain and IP at perimeter security controls, and monitor for unauthorized access attempts using the compromised credentials. If the site was accessed from corporate devices, initiate an incident response procedure to assess potential lateral movement or data exfiltration.
भेजे गए प्रमाण का स्नैपशॉट
- भेजा गया
- लेज़र रिकॉर्ड
- 1
- केस आईडी
PD-20260211-864039- PDF दस्तावेज़
- PDF प्रमाण
प्रमाण का पूरा पाठ
Acceptable Use Policy (AUP): The domain ilmxs.com is engaged in phishing activities, which directly contravenes the AUP prohibiting illegal activities, fraud, and deception.
Terms of Service (TOS): The continued operation of this domain constitutes a violation of the TOS, which reserves the right to suspend or terminate services for any illegal activities, including phishing.
Applicable Laws (CN):
Cybersecurity Law of the People's Republic of China: This law prohibits unauthorized access to networks and the use of phishing schemes to deceive individuals, thereby protecting the integrity of online communications.
Criminal Law of the People's Republic of China (Article 286): This article addresses fraud and stipulates penalties for those who engage in deceptive practices, including phishing.
Regulatory Note: Failure to take immediate action against ilmxs.com may result in regulatory scrutiny and potential liability for the hosting provider under applicable laws. Non-compliance with your own AUP and TOS may also lead to reputational damage and further legal implications.
Data Coverage
नेटवर्क सुरक्षा इंटेलिजेंस
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DigiCert UltraDNS | ilmxs.com |
malicious | Sinkholed |
| Cloudflare DNS | ilmxs.com |
malicious | Sinkholed |
| DNS4EU | ilmxs.com |
malicious | Sinkholed |
| OpenDNS | ilmxs.com |
phishing | Phishing Block |
धमकी प्रतिक्रिया पाइपलाइन
ब्लॉकलिस्ट कवरेज
10 निगरानी वाले बाहरी स्रोत · संग्रहीत स्नैपशॉट 11/08/2026
पहचान समयरेखा
-
डोमेन स्थिति
पहुँच योग्य → पहुँच योग्य नहीं
-
डोमेन स्थिति
पहुँच योग्य नहीं → पहुँच योग्य
सहेजा गया कैप्चर
डोमेन इंटेलिजेंस
तकनीकी विवरणDNS, TLS नाम और समय-मुद्राएँ
ICANN OVERSIGHT
प्रत्यायन और आरएए संदर्भ
प्रत्यायन और आरएए संदर्भ
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
वायरसटोटल विश्लेषण
साइट प्रदर्शन विश्लेषण
Google PageSpeed Insights — mobile performance audit of ilmxs.com · checked Mar 1, 2026
क्या आप इस साइट से प्रभावित हुए?
यदि आपने खाता क्रेडेंशियल, व्यक्तिगत या भुगतान जानकारी दर्ज की है, या इस डोमेन से कोई फ़ाइल डाउनलोड की है, तो तुरंत कार्रवाई करें। घटना की रिपोर्ट करने और अपनी सुरक्षा करने में आपकी सहायता के लिए नीचे संसाधन दिए गए हैं।
अपने स्थानीय अधिकारियों को रिपोर्ट करें
आधिकारिक साइबर अपराध संपर्क, या एक शिकायत ड्राफ्ट बनाएं → प्राप्त करने के लिए अपना देश चुनें।
किसी भी डोमेन की जाँच करें
संग्रहीत ब्लॉकलिस्ट, WHOIS, DNS और सार्वजनिक स्कैन साक्ष्य का उपयोग करके खतरे का विश्लेषण
अभी स्कैन करेंफ़िशिंग की रिपोर्ट करें
संदिग्ध डोमेन हमारे थ्रेट डेटाबेस में जमा करें — समुदाय की सुरक्षा करें
रिपोर्ट करेंसीधा खतरा फीड
हाल की फ़िशिंग रिपोर्टें और उपलब्धता में परिवर्तन देखे गए
निगरानी करेंजानकारी में रहें, सुरक्षित रहें
लाइव खतरों की निगरानी करें या यदि आपको लगता है कि यह एक गलत सकारात्मक है तो इस लिस्टिंग को चुनौती दें।