plasmalabs[.]us
साक्ष्य सारांश
Analysis indicates that the domain plasmalabs.us is actively serving web content over HTTPS with a valid GoDaddy DV certificate. The site resolves to the IPv4 address 13.248.213.45, which is hosted in the AWS Global Accelerator network in the United States (California). The domain was registered on 30 April 2026, and an HTTP GET request returns a 200 status code, confirming that the hosting infrastructure is operational. VirusTotal scans have identified the domain as malicious in three out of ninety‑five vendor engines, and Gridinsoft assigns a trust score of zero out of one hundred, reflecting a high confidence of abuse. AlienVault OTX records the domain in eight distinct threat‑intel pulses, and it appears on three public blocklists. The domain is currently blocked by multiple sink‑hole services, including PhishDestroy, MetaMask, and SEAL, reinforcing the view that it is being used for fraudulent activity. The specific brand or service being spoofed by plasmalabs.us has not been disclosed in the available intelligence, leaving the precise lure unknown. However, the generic phishing classification, combined with the rapid registration date and the use of a reputable TLS certificate, matches a pattern observed in recent phishing campaigns that leverage newly registered domains to gain user trust. Defenders should add 13.248.213.45 and plasmalabs.us to deny‑list configurations, enforce strict URL filtering, and monitor for TLS handshakes that present the GoDaddy DV certificate chain. Network traffic to the AWS Global Accelerator edge should be logged, and any credential submission attempts to the domain should be flagged for investigation. Continuous threat‑intel feeds should be consulted for updates on associated payloads or compromised accounts linked to this infrastructure.
Data Coverage
धमकी प्रतिक्रिया पाइपलाइन
ब्लॉकलिस्ट कवरेज
10 निगरानी वाले बाहरी स्रोत · संग्रहीत स्नैपशॉट 11/08/2026
डोमेन इंटेलिजेंस
तकनीकी विवरणDNS, TLS नाम और समय-मुद्राएँ
वायरसटोटल विश्लेषण
क्या आप इस साइट से प्रभावित हुए?
यदि आपने खाता क्रेडेंशियल, व्यक्तिगत या भुगतान जानकारी दर्ज की है, या इस डोमेन से कोई फ़ाइल डाउनलोड की है, तो तुरंत कार्रवाई करें। घटना की रिपोर्ट करने और अपनी सुरक्षा करने में आपकी सहायता के लिए नीचे संसाधन दिए गए हैं।
अपने स्थानीय अधिकारियों को रिपोर्ट करें
आधिकारिक साइबर अपराध संपर्क, या एक शिकायत ड्राफ्ट बनाएं → प्राप्त करने के लिए अपना देश चुनें।
किसी भी डोमेन की जाँच करें
संग्रहीत ब्लॉकलिस्ट, WHOIS, DNS और सार्वजनिक स्कैन साक्ष्य का उपयोग करके खतरे का विश्लेषण
अभी स्कैन करेंफ़िशिंग की रिपोर्ट करें
संदिग्ध डोमेन हमारे थ्रेट डेटाबेस में जमा करें — समुदाय की सुरक्षा करें
रिपोर्ट करेंसीधा खतरा फीड
हाल की फ़िशिंग रिपोर्टें और उपलब्धता में परिवर्तन देखे गए
निगरानी करेंजानकारी में रहें, सुरक्षित रहें
लाइव खतरों की निगरानी करें या यदि आपको लगता है कि यह एक गलत सकारात्मक है तो इस लिस्टिंग को चुनौती दें।