org-us[.]xyz
“Service Status”
org-us.xyz — असत्यापित. साक्ष्य सारांश: VirusTotal 15/91 (ADMINUSLabs, alphaMountain.ai, BitDefender, Chong Lua Dao, CRDF); URLQuery 2 det.; Spamhaus DBL_PHISH; 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 100/100. रजिस्ट्रार: NiceNIC.
मूल फॉरेंसिक रिकॉर्ड सुरक्षित रखने के लिए नीचे का विस्तृत PhishDestroy AI विश्लेषण अंग्रेज़ी में रखा गया है।
This domain is flagged as a high-risk phishing site designed to impersonate service status portals. Analysis indicates the threat type as a fake login or service impersonation scheme, likely intended to harvest credentials or distribute malware under the guise of a legitimate system status page. The page title "Service Status" reinforces this deception, targeting users expecting operational updates or maintenance notifications. Infrastructure analysis reveals the domain org-us.xyz resolves to IP address 104.21.10.212 and was registered through NICENIC INTERNATIONAL GROUP CO., LIMITED on June 17, 2026. It appears on three security blocklists and is flagged by 15 out of 95 security vendors on VirusTotal. AlienVault OTX includes the domain in two threat intelligence pulses, further corroborating its malicious classification. The creation date suggests recent registration, a common tactic in phishing campaigns to evade detection and maintain operational agility. Mitigation steps for this threat include immediate blocking of the domain and its associated IP address at the network perimeter. Security teams should update endpoint protection rules to detect and prevent access to org-us.xyz and monitor for any attempts to visit the site within their environments. Users should be educated on recognizing fake service portals, particularly those using generic page titles like "Service Status" without verifiable branding or SSL certificates from trusted authorities. Logs should be reviewed for any connections to 104.21.10.212 or related domains registered through the same registrar, as these may indicate broader campaign activity.
नेटवर्क सुरक्षा इंटेलिजेंस Registrar context
धमकी प्रतिक्रिया पाइपलाइन
सार्वजनिक ब्लॉकलिस्ट स्थिति
सहेजा गया कैप्चर
डोमेन इंटेलिजेंस
तकनीकी विवरणडीएनएस, एसएसएल एसएएन, टाइमस्टैम्प
ICANN OVERSIGHT
प्रत्यायन और आरएए संदर्भ
प्रत्यायन और आरएए संदर्भ
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Latest Classified Outcome 2026-08-16 03:16:26 UTC
वायरसटोटल विश्लेषण
साक्ष्य और बाहरी रिपोर्टें
PD-20260630-574403 Recipient: abuse@gen.xyz क्या आप इस साइट से प्रभावित हुए?
यदि आपने खाता क्रेडेंशियल, व्यक्तिगत या भुगतान जानकारी दर्ज की है, या इस डोमेन से कोई फ़ाइल डाउनलोड की है, तो तुरंत कार्रवाई करें। घटना की रिपोर्ट करने और अपनी सुरक्षा करने में आपकी सहायता के लिए नीचे संसाधन दिए गए हैं।
अपने स्थानीय अधिकारियों को रिपोर्ट करें
आधिकारिक साइबर अपराध संपर्क, या एक शिकायत ड्राफ्ट बनाएं → प्राप्त करने के लिए अपना देश चुनें।
किसी भी डोमेन की जाँच करें
संग्रहीत ब्लॉकलिस्ट, WHOIS, DNS और सार्वजनिक स्कैन साक्ष्य का उपयोग करके खतरे का विश्लेषण
अभी स्कैन करेंफ़िशिंग की रिपोर्ट करें
संदिग्ध डोमेन हमारे थ्रेट डेटाबेस में जमा करें — समुदाय की सुरक्षा करें
रिपोर्ट करेंसीधा खतरा फीड
हाल की फ़िशिंग रिपोर्टें और उपलब्धता में परिवर्तन देखे गए
निगरानी करेंजानकारी में रहें, सुरक्षित रहें
लाइव खतरों की निगरानी करें या यदि आपको लगता है कि यह एक गलत सकारात्मक है तो इस लिस्टिंग को चुनौती दें।