सुरक्षा रिपोर्ट पर जाएँ
⚠️
इस डोमेन को दुर्भावनापूर्ण के रूप में चिह्नित किया गया है।
सुरक्षा इंजन एक पहचान की रिपोर्ट कर रहे हैं: 20। अत्यधिक सावधानी बरतें - क्रेडेंशियल या व्यक्तिगत जानकारी दर्ज न करें।
डोमेन सुरक्षा और ख़तरे की आसूचना

seller[.]dfsaop[.]cc

“Shopee”

धमकी भरा फैसला गंभीर 100/100 साक्ष्य स्कोर
उपलब्धता सामग्री अनुपलब्ध नवीनतम अवलोकन में सामग्री अनुपलब्ध थी
वायरस का कुल पता लगाना: 20/91 URLQuery threat systems: 5 alerts ब्रांड प्रतिरूपण: ShopeePay
26/06/2026 ShopeePay 1 Report Sent
रिपोर्ट सारांश

seller.dfsaop.cc — सामग्री अनुपलब्ध (HTTP 502). ब्रांड प्रतिरूपण: ShopeePay; घोटाले का प्रकार: Generic Phishing. साक्ष्य सारांश: VirusTotal 20/91 (alphaMountain.ai, BitDefender, Chong Lua Dao, Cluster25, CRDF); URLQuery 5 alerts; URLScan malicious verdict; Google Safe Browsing flagged; CF Radar malicious; PhishDestroy score 100/100. रजिस्ट्रार: Dominet (HK).

मूल फॉरेंसिक रिकॉर्ड सुरक्षित रखने के लिए नीचे का विस्तृत PhishDestroy AI विश्लेषण अंग्रेज़ी में रखा गया है।

साक्ष्य सारांश
आलोचनात्मक
संदर्भ
06681F87
स्कोर
100/100

This domain, seller.dfsaop.cc, is actively engaged in cryptocurrency wallet phishing operations targeting users of decentralized finance platforms. Analysis indicates the site employs credential harvesting techniques typical of wallet drainer kits, designed to exfiltrate private keys or recovery phrases through deceptive interfaces mimicking legitimate wallet services. No specific brand impersonation has been conclusively identified, though the phishing kit structure suggests compatibility with multiple wallet providers, increasing its potential victim pool. Infrastructure analysis reveals the domain was registered on June 15, 2026, through Dominet (HK) Limited, a registrar frequently associated with high-risk domains. It resolves to the IP address 79.99.78.100, which has been linked to prior phishing campaigns in the cryptocurrency sector. VirusTotal detection metrics show 15 out of 95 security vendors flagging the domain as malicious, a moderate but concerning detection rate that suggests evolving evasion tactics. Google Safe Browsing has classified the site under the SOCIAL_ENGINEERING category, confirming its role in deceptive user interactions. The SSL certificate is issued by Let's Encrypt, a common choice among threat actors to lend superficial legitimacy to phishing endpoints. As of the latest assessment, seller.dfsaop.cc remains operational, with no evidence of takedown or sinkholing. The domain's persistence and active hosting indicate ongoing risk to users who may encounter it through malvertising, compromised ad networks, or social engineering vectors. Organizations are advised to implement DNS-level blocking for the domain and its associated IP, while users should verify wallet addresses through official channels and avoid interacting with unsolicited links. The high-risk classification reflects the domain's confirmed malicious functionality and the irreversible financial impact of cryptocurrency theft, underscoring the need for immediate defensive measures.

VirusTotal
VirusTotal
20 det.
URLQuery
यूआरएलक्वेरी
5 threat alerts
सीएफ रडार
दुर्भावनापूर्ण
URLScan
यूआरएलस्कैन
TLS प्रमाणपत्र
Let's Encrypt / YR1
आयु
2 mo New
देखी गई स्थिति
सामग्री अनुपलब्ध 502
PhishDestroy
विनाश सूची
सूचीबद्ध
Reports Sent
1
डेटा कवरेज VirusTotal 20 / 91 यूआरएलक्वेरी 5 threat-system alerts फ़िशस्टैट्स जाँच नहीं की गई ओटीएक्स no community references सीएफ रडार provider verdict: malicious URLScan capture संग्रहित रिपोर्ट URLScan verdict malicious डीएनएस ब्लॉक जाँच नहीं की गई TLS valid certificate, 37d कौन है 2 mo old स्क्रीनशॉट 3 captures · 3 sources चेन पुनर्निर्देशित करें जांच नहीं की गई
नेटवर्क सुरक्षा इंटेलिजेंस
Threat Detection Systems 5 alerts
Detection System Indicator Verdict Alert
DigiCert UltraDNS seller.dfsaop.cc malicious Sinkholed
CIRA Canadian Shield DNS seller.dfsaop.cc malicious Sinkholed
OpenDNS seller.dfsaop.cc phishing Phishing Block
Cloudflare DNS seller.dfsaop.cc malicious Sinkholed
DNS4EU seller.dfsaop.cc malicious Sinkholed
CF Cloudflare Radar Verdict दुर्भावनापूर्ण
Phishing

धमकी प्रतिक्रिया पाइपलाइन

खोज
Checks
Reports
उपलब्धता
15/15
Sent Report Recorded
Stored sent-report record for registrar Dominet (HK) Limited, hosting provider, 2 abuse contacts
domainabuse@service.aliyun.comreport@abuseradar.com
26/06/2026

सार्वजनिक ब्लॉकलिस्ट स्थिति

सहेजा गया कैप्चर

डोमेन इंटेलिजेंस

डोमेन
URLScan Verdict दुर्भावनापूर्ण score 100 Phishing brand: Shopeebrand: Tiktok report ↗
गूगल सुरक्षित ब्राउज़िंग ध्वजांकित Social engineering checked 26/06/2026
सर्वर / ASN nginx · AS212336 BYTEVIRTLLC ByteVirt LLC, US
IP प्रतिष्ठा abuse score 0/100 0 reports checked 26/06/2026
Registrar (base domain) Dominet (HK) HK(HK)
दुरुपयोग संपर्कdomainabuse@service.aliyun.com, report@abuseradar.com
IP पता 79.99.78.100 US
भौगोलिक स्थानUS Salt Lake City, US
नेटवर्कAS212336 · ByteVirt LLC
रिवर्स IPviewdns.info → rapiddns.io →
Registration (base domain)dfsaop.cc · निर्मित 15/06/2026 (62d · New) Expires 15/06/2027
HTTP स्थिति502 Error
पहली अनुपलब्धता तक का समय 3h
हम क्या मापते हैं पहली संग्रहीत दुरुपयोग रिपोर्ट से लेकर पहली बार अवलोकन तक कि सामग्री अनुपलब्ध थी, बीता हुआ समय। इससे कारण स्थापित नहीं होता.
प्रत्येक रिपोर्ट में क्या शामिल है संग्रहीत आउटगोइंग-रिपोर्ट रिकॉर्ड उस समय उपलब्ध साक्ष्य का संदर्भ दे सकते हैं, जैसे विक्रेता के फैसले, पंजीकरण डेटा, होस्टिंग विवरण, वर्गीकरण, या स्क्रीनशॉट। यह पृष्ठ किसी प्राप्तकर्ता द्वारा वितरित सटीक पेलोड, रसीद, पावती या कार्रवाई का अनुमान नहीं लगाता है।
तकनीकी विवरणडीएनएस, एसएसएल एसएएन, टाइमस्टैम्प
पहली बार पता चला26/06/2026
DOM Analysisanalyzed 26/06/2026score 100/100
IoC Extractionscanned 29/07/20260 wallet · 0 Telegram IoCs
Submitted URLhttp://seller.dfsaop.cc/
नेमसर्वरns1.domainnamens.comns2.domainnamens.com
TLS Fingerprint
TLS Observationvalid from 25/06/2026scanned 26/06/2026
TLS SAN Domainsseller.dfsaop.shopseller.shopeac.ccseller.shpeaa.cc
Case ID
पेज शीर्षक
Shopee
TLS प्रमाणपत्र
Valid transport encryption · जारीकर्ता Let's Encrypt / YR1 · valid for 37 days
तकनीकें · 4 identified
Vue.js
JavaScript frameworks

Vue.js is an open-source model–view–viewmodel JavaScript framework for building user interfaces and single-page applications.

vuejs.org 100% विश्वास
Nginx
Web servers Reverse proxies

Nginx is a web server that can also be used as a reverse proxy, load balancer, mail proxy and HTTP cache.

nginx.org 100% विश्वास
HSTS
सुरक्षा

HTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.

www.rfc-editor.org 100% विश्वास
HTTP/3
Miscellaneous

HTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.

httpwg.org 100% विश्वास
Detected via क्लाउडफ्लेयर रडार · Wappalyzer engine
इस डोमेन की रिपोर्ट करें सबूत जमा करें और दूसरों की सुरक्षा में मदद करें

वायरसटोटल विश्लेषण

20 / 91 सुरक्षा विक्रेताओं ने इस डोमेन को चिह्नित किया
View on VT
Last analyzed
alphaMountain.ai
BitDefender
Chong Lua Dao
Cluster25
CRDF
साइरेडार
Emsisoft
Forcepoint ThreatSeeker
Fortinet
G-Data
Google Safebrowsing
Gridinsoft
कास्परस्की
Lionic
MalwareURL
नेटक्राफ्ट
ओपनफ़िश
SOCRadar
सोफोस
वेबरूट
साइट प्रदर्शन विश्लेषण

Google PageSpeed Insights — mobile performance audit of seller.dfsaop.cc · checked Jun 26, 2026

56
Needs Work
Performance
FCP
10.22s
First Contentful Paint
LCP
15.08s
Largest Contentful Paint
CLS
0
Cumulative Layout Shift
TBT
62ms
Total Blocking Time
SI
10.22s
Speed Index
Powered by Google PageSpeed Insights · Mobile strategy · Scores: 90-100 Good 50-89 Needs Work 0-49 Poor

साक्ष्य और बाहरी रिपोर्टें

Submitted Evidence Snapshot
Sent: Ledger records: 1 Case ID: PD-20260626-0C93FB Recipient: domainabuse@service.aliyun.com
Page title stored with report: Shopee
URLScan evidence VirusTotal evidence URLQuery evidence Screenshot 540.8 KB

क्या आप इस साइट से प्रभावित हुए?

If credentials were compromised, report immediately. Do not engage with recovery scammers.

यदि आपने खाता क्रेडेंशियल, व्यक्तिगत या भुगतान जानकारी दर्ज की है, या इस डोमेन से कोई फ़ाइल डाउनलोड की है, तो तुरंत कार्रवाई करें। घटना की रिपोर्ट करने और अपनी सुरक्षा करने में आपकी सहायता के लिए नीचे संसाधन दिए गए हैं।

यूरोपोल
अपने ईयू देश के लिए आधिकारिक रिपोर्टिंग चैनल ढूंढें
National police directory
रिकवरी ठगों से सावधान रहें! अपराधी जांचकर्ता, वकील या रिकवरी एजेंट होने का नाटक करते हुए पीड़ितों से दोबारा संपर्क कर सकते हैं। अग्रिम शुल्क का भुगतान न करें या क्रेडेंशियल साझा न करें। रिकवरी धोखाधड़ी के बारे में और जानें →

अपने स्थानीय अधिकारियों को रिपोर्ट करें

आधिकारिक साइबर अपराध संपर्क, या एक शिकायत ड्राफ्ट बनाएं → प्राप्त करने के लिए अपना देश चुनें।

97-देश निर्देशिका
एआई-सहायता प्राप्त ड्राफ्ट - घटना विवरण एआई प्रदाता द्वारा संसाधित किया जाता है इसकी स्वयं समीक्षा करें और सबमिट करें

किसी भी डोमेन की जाँच करें

संग्रहीत ब्लॉकलिस्ट, WHOIS, DNS और सार्वजनिक स्कैन साक्ष्य का उपयोग करके खतरे का विश्लेषण

अभी स्कैन करें

फ़िशिंग की रिपोर्ट करें

संदिग्ध डोमेन हमारे थ्रेट डेटाबेस में जमा करें — समुदाय की सुरक्षा करें

रिपोर्ट करें

सीधा खतरा फीड

हाल की फ़िशिंग रिपोर्टें और उपलब्धता में परिवर्तन देखे गए

निगरानी करें

जानकारी में रहें, सुरक्षित रहें

लाइव खतरों की निगरानी करें या यदि आपको लगता है कि यह एक गलत सकारात्मक है तो इस लिस्टिंग को चुनौती दें।

सीधा खतरा फीड इस लिस्टिंग के खिलाफ अपील करें
HTML · IFRAME

इस रिपोर्ट को एम्बेड करें

इस थ्रेट इंटेलिजेंस को अपनी वेबसाइट या ब्लॉग पर साझा करें।

embed.html
<iframe
  src="https://phishdestroy.io/hi/embed/domain/seller.dfsaop.cc"
  title="PhishDestroy threat report for seller.dfsaop.cc"
  width="100%" height="320"
  loading="lazy"
  referrerpolicy="no-referrer"
  sandbox="allow-same-origin allow-popups allow-popups-to-escape-sandbox"
  style="border:0;border-radius:12px;max-width:100%"
></iframe>