priwnotes[.]com
“Privnote - Send notes that will self-destruct after being read”
संग्रहीत अवलोकन
देखा गया शीर्षक अंतर
साक्ष्य सारांश
Analysis of priwnotes.com indicates that the domain was registered on 21 February 2026 and currently resolves to the IPv4 address 66.29.148.38, which is hosted by Namecheap, Inc. under ASN 22612 in the United States. The site presents a page title identical to the legitimate service Privnote, describing a “Send notes that will self‑destruct after being read” feature. The TLS certificate in use is issued by Sectigo Public Server Authentication CA DV R36, confirming that HTTPS is available but providing no assurance of legitimacy. On 24 July 2026 the domain was flagged by five of ninety‑three VirusTotal scanners, indicating that a minority of security vendors have identified malicious activity.
Independent blocklist monitoring shows that the domain is listed on a single security blocklist and is actively blocked by the PhishDestroy filtering service. Nameserver records point to launch1.spaceship.net and launch2.spaceship.net, which are commonly observed in transient hosting environments. The domain’s current operational status is offline, suggesting that the malicious infrastructure may have been taken down or is temporarily inaccessible. The available evidence confirms that priwnotes.com is being used for a generic phishing campaign that leverages the trusted Privnote branding to lure victims into submitting confidential information.
However, the limited number of detection vendor hits and the presence on only one public blocklist leave uncertainty about the scale of the campaign and whether additional payloads or credential‑harvesting pages exist. Defenders should continue to monitor the IP address 66.29.148.38 for any re‑appearance of malicious services, enforce blocks on the domain across corporate web filters, and consider adding the domain to internal deny lists.
Data Coverage
धमकी प्रतिक्रिया पाइपलाइन
ब्लॉकलिस्ट कवरेज
10 निगरानी वाले बाहरी स्रोत · संग्रहीत स्नैपशॉट 11/08/2026
समुदाय रिपोर्ट
1 समुदाय सदस्य ने रिपोर्ट किया; पहली बार 23/07/2025 को देखा गया
- संग्रहीत रिपोर्ट
- 1
- रिपोर्ट किए गए विशिष्ट URL
- 1
सामुदायिक जानकारी
1 सामुदायिक रिपोर्ट
श्रेणीPHISHING
This phisher utilizes fake "privnote.com phishing websites to steal crypto. His addresses can be found here, on an unsecured file on his site: https://priwnotes.com/crypto_addresses.json Any crypto address posted on his site, is automatically replaced with one of his own. The goa
वायरसटोटल विश्लेषण
क्या आप इस साइट से प्रभावित हुए?
यदि आपने खाता क्रेडेंशियल, व्यक्तिगत या भुगतान जानकारी दर्ज की है, या इस डोमेन से कोई फ़ाइल डाउनलोड की है, तो तुरंत कार्रवाई करें। घटना की रिपोर्ट करने और अपनी सुरक्षा करने में आपकी सहायता के लिए नीचे संसाधन दिए गए हैं।
अपने स्थानीय अधिकारियों को रिपोर्ट करें
आधिकारिक साइबर अपराध संपर्क, या एक शिकायत ड्राफ्ट बनाएं → प्राप्त करने के लिए अपना देश चुनें।
किसी भी डोमेन की जाँच करें
संग्रहीत ब्लॉकलिस्ट, WHOIS, DNS और सार्वजनिक स्कैन साक्ष्य का उपयोग करके खतरे का विश्लेषण
अभी स्कैन करेंफ़िशिंग की रिपोर्ट करें
संदिग्ध डोमेन हमारे थ्रेट डेटाबेस में जमा करें — समुदाय की सुरक्षा करें
रिपोर्ट करेंसीधा खतरा फीड
हाल की फ़िशिंग रिपोर्टें और उपलब्धता में परिवर्तन देखे गए
निगरानी करेंजानकारी में रहें, सुरक्षित रहें
लाइव खतरों की निगरानी करें या यदि आपको लगता है कि यह एक गलत सकारात्मक है तो इस लिस्टिंग को चुनौती दें।