MALICIOUS — CRITICAL
mendefa[.]cfd
This domain, mendefa.cfd, is flagged as a generic phishing site designed to harvest user credentials through fraudulent login interfaces.
- VirusTotal
- 14/91
- Blocklists
- No stored match
- उपलब्धता
- सामग्री अनुपलब्ध · HTTP 502
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
mendefa.cfd — सामग्री अनुपलब्ध (HTTP 502). घोटाले का प्रकार: Credential Phishing. साक्ष्य सारांश: VirusTotal 14/91 (alphaMountain.ai, Emsisoft, Fortinet, LevelBlue, Netcraft); URLQuery 2 alerts; Spamhaus DBL_SPAM; CF Radar malicious; PhishDestroy score 98/100. रजिस्ट्रार: NiceNIC.
मूल फॉरेंसिक रिकॉर्ड सुरक्षित रखने के लिए नीचे का विस्तृत PhishDestroy AI विश्लेषण अंग्रेज़ी में रखा गया है।
Evidence Analysis
mendefa.cfd: Credential Harvesting Phishing Site Confirmed
The domain mendefa.cfd is linked to generic phishing and is flagged by 14 of 95 VirusTotal vendors, with one security blocklist listing, indicating potential.
This domain, mendefa.cfd, is flagged as a generic phishing site designed to harvest user credentials through fraudulent login interfaces. Analysis indicates no association with known legitimate brands or drainer kits at this stage, though the infrastructure aligns with typical phishing campaigns. The domain lacks distinctive branding, suggesting a broad or opportunistic targeting strategy rather than a tailored impersonation effort. Infrastructure analysis reveals the following technical indicators: VirusTotal detection score of 0/95, indicating no current antivirus or security vendor flags. The domain was registered on June 26, 2026, through NICENIC INTERNATIONAL GROUP CO., LIMITED, a registrar frequently observed in malicious domain registrations. It resolves to the IP address 188.114.97.3, which has no prior blocklist history in this context. Google Safe Browsing (GSB) status remains unconfirmed, and no blocklist entries were identified at the time of analysis. The domain remains active and under investigation, with no takedown or sinkholing actions observed. Response actions are pending further telemetry and confirmation of victim impact. The remaining risk is elevated due to the domain's operational status and lack of detection coverage across security platforms. Users are advised to block the domain at the DNS level and monitor network logs for connections to 188.114.97.3. Security teams should treat any interaction with mendefa.cfd as a potential credential compromise event and initiate password resets for affected accounts.
Stored source results
Recorded verdicts and infrastructure observations for this domain.
डेटा कवरेज12 recorded checks
नेटवर्क सुरक्षा इंटेलिजेंस Registrar context
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Cloudflare DNS | mendefa.cfd |
malicious | Sinkholed |
| OpenDNS | mendefa.cfd |
phishing | Phishing Block |
धमकी प्रतिक्रिया पाइपलाइन
सार्वजनिक ब्लॉकलिस्ट स्थिति
सहेजा गया कैप्चर
डोमेन इंटेलिजेंस
तकनीकी विवरणडीएनएस, एसएसएल एसएएन, टाइमस्टैम्प
SHORTDOT ज़ोन · सार्वजनिक साक्ष्य
.cfd
ShortDot zone evidence
ShortDot zone evidence
The linked repository preserves daily zone observations across seven ShortDot-operated TLDs, including registration volume and abuse-related indicators. This registry context is supporting background and is not an independent detection for the domain in this report.
ICANN OVERSIGHT
प्रत्यायन और आरएए संदर्भ
प्रत्यायन और आरएए संदर्भ
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Latest Classified Outcome 2026-08-09 04:06:36 UTC
तकनीकें · 3 identified
Cloudflare Browser Insights is a tool that measures the performance of websites from the perspective of users.
www.cloudflare.com 100% विश्वासCloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com 100% विश्वासHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100% विश्वासवायरसटोटल विश्लेषण
साक्ष्य और बाहरी रिपोर्टेंIndependent lookups and source reports
PD-20260628-BF6DB6 Recipient: abuse@gen.xyz Victim safety and official reportingImmediate actions and verified reporting channels
यदि आपने खाता क्रेडेंशियल, व्यक्तिगत या भुगतान जानकारी दर्ज की है, या इस डोमेन से कोई फ़ाइल डाउनलोड की है, तो तुरंत कार्रवाई करें। घटना की रिपोर्ट करने और अपनी सुरक्षा करने में आपकी सहायता के लिए नीचे संसाधन दिए गए हैं।
अपने स्थानीय अधिकारियों को रिपोर्ट करें
आधिकारिक साइबर अपराध संपर्क, या एक शिकायत ड्राफ्ट बनाएं → प्राप्त करने के लिए अपना देश चुनें।