सुरक्षा रिपोर्ट पर जाएँ
⚠️
इस डोमेन को दुर्भावनापूर्ण के रूप में चिह्नित किया गया है।
सुरक्षा इंजन एक पहचान की रिपोर्ट कर रहे हैं: 10। किसी मैच की रिपोर्ट करने वाली सार्वजनिक ब्लॉक सूचियाँ: 2। अत्यधिक सावधानी बरतें - क्रेडेंशियल या व्यक्तिगत जानकारी दर्ज न करें।
ABUSE NOTICE · 7D+ OPEN Outgoing abuse reports are recorded; the latest stored availability evidence still shows the domain reachable.
Notification and current-status evidence

The sent-report ledger records the first outgoing report at . The recorded recipient is abuse@cosmotown.com. The latest stored availability evidence still shows the domain reachable; 2 months has elapsed since the first outgoing report.

ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.

Elapsed since first report
2 months
Reports sent
1
Latest case ID
PD-20260515-768D1B
Current status
HTTP 200 at latest stored check
डोमेन सुरक्षा और ख़तरे की आसूचना

mohimen[.]com

mohimen.com की फ़िशिंग और सुरक्षा जाँच

“Home - MOHI”

धमकी भरा फैसला गंभीर 95/100 साक्ष्य स्कोर
उपलब्धता अंतिम ज्ञात सक्रिय नवीनतम संग्रहीत रीचैबिलिटी अवलोकन
जोखिम संकेत
वायरस का कुल पता लगाना: 10/91 Spamhaus DBL: DBL_SPAM संग्रहीत ब्लॉकलिस्ट मिलान: 2 URLQuery threat systems: 3 alerts घोटाले का प्रकार: Credential Phishing अंतिम ज्ञात सक्रिय
10/91 VT URLQuery: 3 threat alerts 15/05/2026 2 Blocklists प्रमाणपत्र फिशिंग 1 Report Sent US US
रिपोर्ट सारांश

mohimen.com — अंतिम ज्ञात सक्रिय (HTTP 200). घोटाले का प्रकार: Credential Phishing. साक्ष्य सारांश: VirusTotal 10/91 (alphaMountain.ai, Antiy-AVL, BitDefender, Chong Lua Dao, Forcepoint ThreatSeeker); URLQuery 3 alerts; Spamhaus DBL_SPAM; 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 95/100. रजिस्ट्रार: TuringSign.

मूल फॉरेंसिक रिकॉर्ड सुरक्षित रखने के लिए नीचे का विस्तृत PhishDestroy AI विश्लेषण अंग्रेज़ी में रखा गया है।

साक्ष्य सारांश
आलोचनात्मक
संदर्भ
F6A52ECD
स्कोर
95/100

The domain mohimen.com has been confirmed as a high-risk crypto credential theft site designed to harvest wallet login credentials and private keys. Analysis indicates the infrastructure was actively targeting cryptocurrency users through deceptive interfaces mimicking legitimate wallet services. The domain is currently offline, though prior activity suggests it may have been part of a broader campaign to drain digital assets from compromised accounts. Infrastructure analysis reveals mohimen.com was registered on October 27, 2024, through TuringSign Inc. d/b/a Cosmotown, a registrar frequently associated with malicious domains. The site resolved to the IP address 104.234.134.77 and employed a Let's Encrypt SSL certificate to present a false sense of legitimacy. Detection metrics show the domain was flagged by 13 of 95 security vendors on VirusTotal, while Gridinsoft assigned a trust score of 0/100. Additionally, the domain appeared on three distinct security blocklists, including MetaMask and PhishDestroy, further corroborating its malicious classification. Technologies detected on the site included WordPress, MySQL, PHP, jQuery Migrate, jQuery, and HTTP/3, which are commonly exploited in phishing operations to facilitate credential exfiltration. Current status indicates mohimen.com has been taken offline, though the underlying infrastructure may remain dormant for future reuse. Organizations and individuals are advised to block the domain and associated IP address (104.234.134.77) at the network level. Cryptocurrency users should verify wallet interfaces against official sources and enable multi-factor authentication where available. Security teams are recommended to monitor for indicators of compromise, including the domain's creation date, registrar details, and SSL certificate issuance patterns, as these may reappear in related campaigns. Proactive threat hunting for similar WordPress-based credential theft sites is strongly encouraged.

VirusTotal
VirusTotal
10 det.
URLQuery
यूआरएलक्वेरी
3 threat alerts
URLScan
यूआरएलस्कैन
TLS प्रमाणपत्र
Let's Encrypt
आयु
1.8 yr
देखी गई स्थिति
अंतिम ज्ञात सक्रिय 200
PhishDestroy
विनाश सूची
सूचीबद्ध
Reports Sent
1
डेटा कवरेज VirusTotal 10 / 91 यूआरएलक्वेरी 3 threat-system alerts फ़िशस्टैट्स checked — no match recorded ओटीएक्स no community references सीएफ रडार scan completed URLScan capture संग्रहित रिपोर्ट URLScan verdict विश्लेषण पूरा हुआ डीएनएस ब्लॉक जाँच नहीं की गई TLS valid certificate, 74d कौन है 22 mo old स्क्रीनशॉट 2 captures · 2 sources चेन पुनर्निर्देशित करें जांच नहीं की गई
नेटवर्क सुरक्षा इंटेलिजेंस
Threat Detection Systems 3 alerts
Detection System Indicator Verdict Alert
Quad9 DNS mohimen.com malicious Sinkholed
Hagezi Threat Feed mohimen.com malicious Sinkholed
DNS4EU mohimen.com malicious Sinkholed

धमकी प्रतिक्रिया पाइपलाइन

खोज
Checks
Reports
उपलब्धता
13/14
Sent Report Recorded
Stored sent-report record for registrar TuringSign Inc. d/b/a Cosmotown, hosting provider, 2 abuse contacts
abuse@cosmotown.comreport@abuseradar.com
15/05/2026

सार्वजनिक ब्लॉकलिस्ट स्थिति

सहेजा गया कैप्चर

पेज शीर्षक
Home - MOHI
TLS प्रमाणपत्र
Valid transport encryption · जारीकर्ता Let's Encrypt · valid for 74 days

डोमेन इंटेलिजेंस

डोमेन
URLScan Verdict विश्लेषण पूरा हुआ score 0 report ↗
सर्वर / ASN AS40676 Psychz Networks
IP प्रतिष्ठा abuse score 0/100 1 report checked 13/07/2026
रजिस्ट्रार TuringSign
दुरुपयोग संपर्कabuse@cosmotown.com, report@abuseradar.com
IP पता 104.234.134.77 US
भौगोलिक स्थानUS Dallas, US
नेटवर्कAS40676 · ONTAR-40 (Velcom INC)
रिवर्स IPviewdns.info → rapiddns.io →
पंजीकरणनिर्मित 27/10/2024
Elapsed Since First Report 4h
हम क्या मापते हैं Raw elapsed time since the first stored abuse report. It is not a registrar response-time measurement. Latest observed status: अंतिम ज्ञात सक्रिय.
प्रत्येक रिपोर्ट में क्या शामिल है संग्रहीत आउटगोइंग-रिपोर्ट रिकॉर्ड उस समय उपलब्ध साक्ष्य का संदर्भ दे सकते हैं, जैसे विक्रेता के फैसले, पंजीकरण डेटा, होस्टिंग विवरण, वर्गीकरण, या स्क्रीनशॉट। यह पृष्ठ किसी प्राप्तकर्ता द्वारा वितरित सटीक पेलोड, रसीद, पावती या कार्रवाई का अनुमान नहीं लगाता है।
HTTP स्थिति200
तकनीकी विवरणडीएनएस, एसएसएल एसएएन, टाइमस्टैम्प
पहली बार पता चला15/05/2026
IoC Extractionscanned 29/07/20260 wallet · 0 Telegram IoCs
Submitted URLhttp://mohimen.com/
नेमसर्वरns1.hostseba.comns2.hostseba.com
TLS Fingerprint
TLS Observationvalid from 10/04/2026scanned 16/05/2026
Favicon Hash
Case ID
ICANN OVERSIGHT

प्रत्यायन और आरएए संदर्भ

Registrar accreditation and DNS abuse obligations

For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.

Accreditation is a contract, not a safety certification.

RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.

मान्यता एक अनुबंध है, सुरक्षा की मुहर नहीं। ICANN शुल्क सत्यापित करें RAA §3.18 पढ़ें PHISHDESTROY INVESTIGATIONICANN funding, contracts, and DNS abuse oversight
Accountability draft कुछ भी अपने आप नहीं भेजा जाता।
तकनीकें · 6 identified
WordPress
CMS Blogs

WordPress is a free and open-source content management system written in PHP and paired with a MySQL or MariaDB database. Features include a plugin architecture and a template system.

wordpress.org 100% विश्वास
MySQL
Databases

MySQL is an open-source relational database management system.

mysql.com 100% विश्वास
PHP
Programming languages

PHP is a general-purpose scripting language used for web development.

php.net 100% विश्वास
jQuery Migrate
JavaScript libraries

Query Migrate is a javascript library that allows you to preserve the compatibility of your jQuery code developed for versions of jQuery older than 1.9.

github.com 100% विश्वास
jQuery
JavaScript libraries

jQuery is a JavaScript library which is a free, open-source software designed to simplify HTML DOM tree traversal and manipulation, as well as event handling, CSS animation, and Ajax.

jquery.com 100% विश्वास
HTTP/3
Miscellaneous

HTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.

httpwg.org 100% विश्वास
Detected via क्लाउडफ्लेयर रडार · Wappalyzer engine
इस डोमेन की रिपोर्ट करें सबूत जमा करें और दूसरों की सुरक्षा में मदद करें

वायरसटोटल विश्लेषण

10 / 91 सुरक्षा विक्रेताओं ने इस डोमेन को चिह्नित किया
View on VT
Last analyzed Previous stored snapshot: 13 detections
alphaMountain.ai
Antiy-AVL
BitDefender
Chong Lua Dao
Forcepoint ThreatSeeker
Fortinet
G-Data
Gridinsoft
Lionic
SOCRadar
साइट प्रदर्शन विश्लेषण

Google PageSpeed Insights — mobile performance audit of mohimen.com · checked Jun 26, 2026

69
Needs Work
Performance
FCP
2.91s
First Contentful Paint
LCP
6.46s
Largest Contentful Paint
CLS
0
Cumulative Layout Shift
TBT
0ms
Total Blocking Time
SI
4.85s
Speed Index
Powered by Google PageSpeed Insights · Mobile strategy · Scores: 90-100 Good 50-89 Needs Work 0-49 Poor
साइट कॉन्फ़िगरेशन विश्लेषण
Stored observations are retained with their original collection time.
robots.txt Present · HTTP 200
/wp-admin/ /wp-admin/admin-ajax.php

साक्ष्य और बाहरी रिपोर्टें

Submitted Evidence Snapshot
Sent: Ledger records: 1 Case ID: PD-20260515-768D1B Recipient: abuse@cosmotown.com
Page title stored with report: Home - MOHI
URLScan evidence VirusTotal evidence URLQuery evidence Screenshot 192.4 KB

क्या आप इस साइट से प्रभावित हुए?

If credentials were compromised, report immediately. Do not engage with recovery scammers.

यदि आपने खाता क्रेडेंशियल, व्यक्तिगत या भुगतान जानकारी दर्ज की है, या इस डोमेन से कोई फ़ाइल डाउनलोड की है, तो तुरंत कार्रवाई करें। घटना की रिपोर्ट करने और अपनी सुरक्षा करने में आपकी सहायता के लिए नीचे संसाधन दिए गए हैं।

यूरोपोल
अपने ईयू देश के लिए आधिकारिक रिपोर्टिंग चैनल ढूंढें
National police directory
रिकवरी ठगों से सावधान रहें! अपराधी जांचकर्ता, वकील या रिकवरी एजेंट होने का नाटक करते हुए पीड़ितों से दोबारा संपर्क कर सकते हैं। अग्रिम शुल्क का भुगतान न करें या क्रेडेंशियल साझा न करें। रिकवरी धोखाधड़ी के बारे में और जानें →

अपने स्थानीय अधिकारियों को रिपोर्ट करें

आधिकारिक साइबर अपराध संपर्क, या एक शिकायत ड्राफ्ट बनाएं → प्राप्त करने के लिए अपना देश चुनें।

97-देश निर्देशिका
एआई-सहायता प्राप्त ड्राफ्ट - घटना विवरण एआई प्रदाता द्वारा संसाधित किया जाता है इसकी स्वयं समीक्षा करें और सबमिट करें

किसी भी डोमेन की जाँच करें

संग्रहीत ब्लॉकलिस्ट, WHOIS, DNS और सार्वजनिक स्कैन साक्ष्य का उपयोग करके खतरे का विश्लेषण

अभी स्कैन करें

फ़िशिंग की रिपोर्ट करें

संदिग्ध डोमेन हमारे थ्रेट डेटाबेस में जमा करें — समुदाय की सुरक्षा करें

रिपोर्ट करें

सीधा खतरा फीड

हाल की फ़िशिंग रिपोर्टें और उपलब्धता में परिवर्तन देखे गए

निगरानी करें

जानकारी में रहें, सुरक्षित रहें

लाइव खतरों की निगरानी करें या यदि आपको लगता है कि यह एक गलत सकारात्मक है तो इस लिस्टिंग को चुनौती दें।

सीधा खतरा फीड इस लिस्टिंग के खिलाफ अपील करें
HTML · IFRAME

इस रिपोर्ट को एम्बेड करें

इस थ्रेट इंटेलिजेंस को अपनी वेबसाइट या ब्लॉग पर साझा करें।

embed.html
<iframe
  src="https://phishdestroy.io/hi/embed/domain/mohimen.com"
  title="PhishDestroy threat report for mohimen.com"
  width="100%" height="320"
  loading="lazy"
  referrerpolicy="no-referrer"
  sandbox="allow-same-origin allow-popups allow-popups-to-escape-sandbox"
  style="border:0;border-radius:12px;max-width:100%"
></iframe>

एक अत्यंत सच्चा धन्यवाद-पत्र

व्यंग्यात्मक मसौदा जनरेटर

प्राप्तकर्ता
शुल्क संदर्भ

यह व्यंग्यात्मक मसौदा है। शुल्क के आंकड़े अनुमान हैं; इन्हें इस डोमेन से ठीक-ठीक जोड़ने का दावा नहीं किया जाता।