Notification and current-status evidence
The sent-report ledger records the first outgoing report at .
The recorded recipient is abuse@microsoft.com.
The latest stored availability evidence still shows the domain reachable; 5 months has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
qp1111[.]vip
“登录”
qp1111.vip — असत्यापित. घोटाले का प्रकार: Credential Phishing. साक्ष्य सारांश: VirusTotal 11/91 (alphaMountain.ai, BitDefender, Chong Lua Dao, Forcepoint ThreatSeeker, Fortinet); URLQuery 1 alert; PhishDestroy score 88/100. रजिस्ट्रार: Dynadot.
मूल फॉरेंसिक रिकॉर्ड सुरक्षित रखने के लिए नीचे का विस्तृत PhishDestroy AI विश्लेषण अंग्रेज़ी में रखा गया है।
This domain, qp1111.vip, is identified as a generic phishing site designed to harvest user credentials through a fake login interface. The page title, displayed in Chinese as '登录' (Login), suggests targeting of Mandarin-speaking users, though no specific brand impersonation is confirmed. Analysis of the infrastructure reveals no direct ties to known crypto drainer kits or advanced phishing frameworks, but the presence of a basic credential capture mechanism aligns with opportunistic phishing campaigns. Infrastructure analysis reveals multiple high-risk indicators. The domain was registered on March 04, 2026, through Dynadot LLC, a registrar frequently exploited for malicious registrations. It resolves to the IP address 20.255.104.129, a host associated with prior phishing activity. VirusTotal reports 4 out of 95 security vendors flagging the domain as malicious, while it appears on one security blocklist. The SSL certificate, issued by Let's Encrypt (R12), provides no inherent trust, as it is commonly abused for short-lived phishing domains. Google Safe Browsing (GSB) does not currently list the domain, though this may reflect its recent takedown rather than benign status. The domain is currently offline, likely due to takedown actions or infrastructure suspension. However, residual risk persists due to the registrar's history of hosting malicious domains and the potential for rapid redeployment under a new domain or IP. Users who interacted with the site should assume credential exposure and initiate password resets for any accounts accessed during the period of activity. Organizations are advised to monitor for related domains registered through the same registrar or resolving to the same IP range, as threat actors often reuse infrastructure across campaigns.
नेटवर्क सुरक्षा इंटेलिजेंस
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DNS4EU | qp1111.vip |
malicious | Sinkholed |
धमकी प्रतिक्रिया पाइपलाइन
सार्वजनिक ब्लॉकलिस्ट स्थिति
सहेजा गया कैप्चर
डोमेन इंटेलिजेंस
तकनीकी विवरणडीएनएस, एसएसएल एसएएन, टाइमस्टैम्प
ICANN OVERSIGHT
प्रत्यायन और आरएए संदर्भ
प्रत्यायन और आरएए संदर्भ
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
तकनीकें · 3 identified
Legacy JavaScript library — DOM manipulation and AJAX helpers. Still widely present on older sites.
Legacy JavaScript library — DOM manipulation and AJAX helpers. Still widely present on older sites.
Fast, small JavaScript library simplifying HTML manipulation, event handling, and Ajax.
वायरसटोटल विश्लेषण
संग्रहीत साक्ष्य
साइट प्रदर्शन विश्लेषण
Google PageSpeed Insights — mobile performance audit of qp1111.vip · checked Mar 4, 2026
साक्ष्य और बाहरी रिपोर्टें
PD-20260304-3AC105 Recipient: abuse@microsoft.com क्या आप इस साइट से प्रभावित हुए?
यदि आपने खाता क्रेडेंशियल, व्यक्तिगत या भुगतान जानकारी दर्ज की है, या इस डोमेन से कोई फ़ाइल डाउनलोड की है, तो तुरंत कार्रवाई करें। घटना की रिपोर्ट करने और अपनी सुरक्षा करने में आपकी सहायता के लिए नीचे संसाधन दिए गए हैं।
अपने स्थानीय अधिकारियों को रिपोर्ट करें
आधिकारिक साइबर अपराध संपर्क, या एक शिकायत ड्राफ्ट बनाएं → प्राप्त करने के लिए अपना देश चुनें।
किसी भी डोमेन की जाँच करें
संग्रहीत ब्लॉकलिस्ट, WHOIS, DNS और सार्वजनिक स्कैन साक्ष्य का उपयोग करके खतरे का विश्लेषण
अभी स्कैन करेंफ़िशिंग की रिपोर्ट करें
संदिग्ध डोमेन हमारे थ्रेट डेटाबेस में जमा करें — समुदाय की सुरक्षा करें
रिपोर्ट करेंसीधा खतरा फीड
हाल की फ़िशिंग रिपोर्टें और उपलब्धता में परिवर्तन देखे गए
निगरानी करेंजानकारी में रहें, सुरक्षित रहें
लाइव खतरों की निगरानी करें या यदि आपको लगता है कि यह एक गलत सकारात्मक है तो इस लिस्टिंग को चुनौती दें।