Notification and current-status evidence
The sent-report ledger records the first outgoing report at .
The recorded recipient is abuse@trustname.com.
The latest stored availability evidence still shows the domain reachable; 3 months has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
promopassagembus[.]com
“Passagens de onibus com melhor preco | Viaja Brasil”
promopassagembus.com — ढका हुआ · पहुंच योग्य. घोटाले का प्रकार: Generic Phishing. साक्ष्य सारांश: VirusTotal 16/94 (ADMINUSLabs, alphaMountain.ai, BitDefender, Chong Lua Dao, CRDF); Google Safe Browsing flagged; cloaking observed; PhishDestroy score 95/100. रजिस्ट्रार: Fewmoretaps OU d/b/a T….
मूल फॉरेंसिक रिकॉर्ड सुरक्षित रखने के लिए नीचे का विस्तृत PhishDestroy AI विश्लेषण अंग्रेज़ी में रखा गया है।
The domain promopassagembus.com has been identified as a phishing site specifically targeting users seeking bus tickets under the guise of offering discounted fares through Viaja Brasil. Analysis confirms this domain operated as a credential and payment harvesting platform, impersonating legitimate bus ticket vendors. The site is currently offline, but prior activity indicates a high-risk threat classification. Infrastructure analysis reveals the domain was registered on April 20, 2026, through Fewmoretaps OU d/b/a Trustname.com. It resolved to the IP address 216.150.1.1 and employed a Let's Encrypt SSL certificate to appear legitimate. Security vendors flagged the domain with 17 detections out of 95 on VirusTotal, while Google Safe Browsing specifically marked it for social engineering. The domain appeared on two security blocklists and was blocked by PhishDestroy and InversionDNS. Additional technical indicators include the use of Node.js, React, Vercel, Next.js, HSTS, Google AdSense, and Webpack, suggesting a sophisticated frontend designed to mimic legitimate ticketing platforms. The domain has since been taken offline, but users who may have interacted with it should assume credential and payment information was compromised. Organizations are advised to block the domain and associated IP at the network level, monitor for related phishing campaigns, and educate users on recognizing fraudulent ticketing sites. Security teams should review logs for connections to 216.150.1.1 and the domain promopassagembus.com, particularly in regions where Viaja Brasil operates. If financial data was entered, affected parties should initiate fraud monitoring and consider reissuing payment cards.
नेटवर्क सुरक्षा इंटेलिजेंस Registrar context
धमकी प्रतिक्रिया पाइपलाइन
सार्वजनिक ब्लॉकलिस्ट स्थिति
सहेजा गया कैप्चर
डोमेन इंटेलिजेंस
तकनीकी विवरणडीएनएस, एसएसएल एसएएन, टाइमस्टैम्प
ICANN OVERSIGHT
प्रत्यायन और आरएए संदर्भ
प्रत्यायन और आरएए संदर्भ
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
तकनीकें · 7 identified
Node.js is an open-source, cross-platform, JavaScript runtime environment that executes JavaScript code outside a web browser.
nodejs.org 100% विश्वासReact is an open-source JavaScript library for building user interfaces or UI components.
reactjs.org 100% विश्वासNext.js is a React framework for developing single page Javascript applications.
nextjs.org 100% विश्वासHTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org 100% विश्वासGoogle AdSense is a program run by Google through which website publishers serve advertisements that are targeted to the site content and audience.
www.google.com 100% विश्वासवायरसटोटल विश्लेषण
साइट प्रदर्शन विश्लेषण
Google PageSpeed Insights — mobile performance audit of promopassagembus.com · checked Jun 26, 2026
साक्ष्य और बाहरी रिपोर्टें
PD-20260424-D900E4 Recipient: abuse@trustname.com क्या आप इस साइट से प्रभावित हुए?
यदि आपने खाता क्रेडेंशियल, व्यक्तिगत या भुगतान जानकारी दर्ज की है, या इस डोमेन से कोई फ़ाइल डाउनलोड की है, तो तुरंत कार्रवाई करें। घटना की रिपोर्ट करने और अपनी सुरक्षा करने में आपकी सहायता के लिए नीचे संसाधन दिए गए हैं।
अपने स्थानीय अधिकारियों को रिपोर्ट करें
आधिकारिक साइबर अपराध संपर्क, या एक शिकायत ड्राफ्ट बनाएं → प्राप्त करने के लिए अपना देश चुनें।
किसी भी डोमेन की जाँच करें
संग्रहीत ब्लॉकलिस्ट, WHOIS, DNS और सार्वजनिक स्कैन साक्ष्य का उपयोग करके खतरे का विश्लेषण
अभी स्कैन करेंफ़िशिंग की रिपोर्ट करें
संदिग्ध डोमेन हमारे थ्रेट डेटाबेस में जमा करें — समुदाय की सुरक्षा करें
रिपोर्ट करेंसीधा खतरा फीड
हाल की फ़िशिंग रिपोर्टें और उपलब्धता में परिवर्तन देखे गए
निगरानी करेंजानकारी में रहें, सुरक्षित रहें
लाइव खतरों की निगरानी करें या यदि आपको लगता है कि यह एक गलत सकारात्मक है तो इस लिस्टिंग को चुनौती दें।