सुरक्षा रिपोर्ट पर जाएँ
⚠️
इस डोमेन को दुर्भावनापूर्ण के रूप में चिह्नित किया गया है।
सुरक्षा इंजन एक पहचान की रिपोर्ट कर रहे हैं: 12। अत्यधिक सावधानी बरतें - क्रेडेंशियल या व्यक्तिगत जानकारी दर्ज न करें।
ABUSE NOTICE · 7D+ OPEN Outgoing abuse reports are recorded; the latest stored availability evidence still shows the domain reachable.
Notification and current-status evidence

The sent-report ledger records the first outgoing report at . The recorded recipient is wzryvip88@outlook.com. The latest stored availability evidence still shows the domain reachable; 6 months has elapsed since the first outgoing report.

ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.

Elapsed since first report
6 months
Reports sent
1
Latest case ID
PD-20260204-8D9B9B
Current status
Observed active at latest stored check
डोमेन सुरक्षा और ख़तरे की आसूचना

smtp-1[.]coolhair[.]com[.]cn

“Apache2 Ubuntu Default Page: It works”

धमकी भरा फैसला गंभीर 88/100 साक्ष्य स्कोर
उपलब्धता असत्यापित वर्तमान पहुंच योग्यता असत्यापित है
वायरस का कुल पता लगाना: 12/91 URLQuery threat systems: 3 alerts
04/02/2026 1 Report Sent
रिपोर्ट सारांश

smtp-1.coolhair.com.cn — असत्यापित. साक्ष्य सारांश: VirusTotal 12/91 (ADMINUSLabs, BitDefender, CyRadar, Forcepoint ThreatSeeker, Fortinet); URLQuery 3 alerts; PhishDestroy score 88/100. रजिस्ट्रार: 广东时代互联科技有限公司.

मूल फॉरेंसिक रिकॉर्ड सुरक्षित रखने के लिए नीचे का विस्तृत PhishDestroy AI विश्लेषण अंग्रेज़ी में रखा गया है।

साक्ष्य सारांश
आलोचनात्मक
संदर्भ
44F68613
स्कोर
88/100

Analysis of smtp-1.coolhair.com.cn indicates the domain was registered on 2026-02-21 through 广东时代互联科技有限公司. The authoritative nameservers ns1.nowcndns.com and ns2.nowcndns.com resolve the name to 172.86.90.240, an address owned by AS14956 RouterHosting LLC in the United States. No TLS certificate is presented, and an HTTP request returns the default Apache2 Ubuntu page with the title “Apache2 Ubuntu Default Page: It works”, suggesting a misconfigured web server rather than a crafted phishing landing page. Gridinsoft assigns a trust score of 0/100, and the domain appears on a single security blocklist.

VirusTotal reports 15 of 93 scanners flagging the domain, and PhishDestroy has listed it as blocked. The threat type is recorded as generic phishing, and the current operational status is offline. Confidence in the phishing intent derives from the classification by multiple vendors and the blocklisting actions, but the lack of a visible malicious payload or credential‑collection page limits direct attribution of a specific campaign. Defenders should continue to block the domain and its resolved IP at perimeter firewalls and DNS filtering solutions.

Ongoing monitoring of the registrar and the nowcndns.com name‑server infrastructure is advisable, as changes could reactivate the host. Adding the IP to threat‑intel feeds and ensuring email security gateways reference the latest blocklist entries will reduce exposure. Given the recent creation date and the low trust score, the domain should be treated as high‑priority for proactive mitigation despite its offline state.

VirusTotal
VirusTotal
12 det.
URLQuery
यूआरएलक्वेरी
3 threat alerts
URLScan
यूआरएलस्कैन
देखी गई स्थिति
असत्यापित
PhishDestroy
विनाश सूची
सूचीबद्ध
Reports Sent
1
डेटा कवरेज VirusTotal 12 / 91 यूआरएलक्वेरी 3 threat-system alerts फ़िशस्टैट्स checked — no match recorded ओटीएक्स no community references सीएफ रडार scan completed URLScan capture संग्रहित रिपोर्ट URLScan verdict विश्लेषण पूरा हुआ डीएनएस ब्लॉक जाँच नहीं की गई TLS कोई प्रमाणपत्र डेटा नहीं कौन है not parsed स्क्रीनशॉट 3 captures · 3 sources चेन पुनर्निर्देशित करें जांच नहीं की गई
नेटवर्क सुरक्षा इंटेलिजेंस
Threat Detection Systems 3 alerts
Detection System Indicator Verdict Alert
OpenDNS smtp-1.coolhair.com.cn phishing Phishing Block
Hagezi Threat Feed smtp-1.coolhair.com.cn malicious Sinkholed
DNS4EU smtp-1.coolhair.com.cn malicious Sinkholed

धमकी प्रतिक्रिया पाइपलाइन

खोज
Checks
Reports
उपलब्धता
15/16
Sent Report Recorded
Stored sent-report record for registrar 广东时代互联科技有限公司, hosting provider, 2 abuse contacts
wzryvip88@outlook.comabuse-reports@cloudzy.com
04/02/2026

सार्वजनिक ब्लॉकलिस्ट स्थिति

सहेजा गया कैप्चर

डोमेन इंटेलिजेंस

डोमेन
URLScan Verdict विश्लेषण पूरा हुआ score 0 report ↗
सर्वर / ASN Apache/2.4.58 (Ubuntu) · AS14956 RouterHosting LLC
IP प्रतिष्ठा abuse score 0/100 0 reports checked 01/08/2026
Registrar (base domain) 广东时代互联科技有限公司 CN(CN)
दुरुपयोग संपर्कwzryvip88@outlook.com, abuse-reports@cloudzy.com
IP पता 172.86.90.240 US
भौगोलिक स्थानUS Dallas, US
नेटवर्कAS14956 · RouterHosting LLC
रिवर्स IPviewdns.info → rapiddns.io →
Elapsed Since First Report 92 days
हम क्या मापते हैं Raw elapsed time since the first stored abuse report. It is not a registrar response-time measurement. Latest observed status: असत्यापित.
प्रत्येक रिपोर्ट में क्या शामिल है संग्रहीत आउटगोइंग-रिपोर्ट रिकॉर्ड उस समय उपलब्ध साक्ष्य का संदर्भ दे सकते हैं, जैसे विक्रेता के फैसले, पंजीकरण डेटा, होस्टिंग विवरण, वर्गीकरण, या स्क्रीनशॉट। यह पृष्ठ किसी प्राप्तकर्ता द्वारा वितरित सटीक पेलोड, रसीद, पावती या कार्रवाई का अनुमान नहीं लगाता है।
तकनीकी विवरणडीएनएस, एसएसएल एसएएन, टाइमस्टैम्प
पहली बार पता चला04/02/2026
DOM Analysisanalyzed 23/04/2026score 88/100
IoC Extractionscanned 01/08/20260 wallet · 0 Telegram IoCs
Submitted URLhttp://smtp-1.coolhair.com.cn/
नेमसर्वरns1.nowcndns.com
TLS Observationscanned 15/08/2026
Case ID
पेज शीर्षक
Apache2 Ubuntu Default Page: It works
इस डोमेन की रिपोर्ट करें सबूत जमा करें और दूसरों की सुरक्षा में मदद करें

वायरसटोटल विश्लेषण

12 / 91 सुरक्षा विक्रेताओं ने इस डोमेन को चिह्नित किया
View on VT
Last analyzed Previous stored snapshot: 15 detections
ADMINUSLabs
BitDefender
साइरेडार
Forcepoint ThreatSeeker
Fortinet
G-Data
गूगल सुरक्षित ब्राउज़िंग
Gridinsoft
Lionic
सोफोस
VIPRE
वेबरूट

संग्रहीत साक्ष्य

Wayback Machine Snapshot
साक्ष्य समीक्षा के लिए एक ऐतिहासिक स्नैपशॉट उपलब्ध है
View Archive

साक्ष्य और बाहरी रिपोर्टें

Submitted Evidence Snapshot
Sent: Ledger records: 1 Case ID: PD-20260204-8D9B9B Recipient: wzryvip88@outlook.com
URLScan evidence VirusTotal evidence URLQuery evidence Screenshot 89.7 KB
Blocklist hits included with submission: ओपनफ़िश

क्या आप इस साइट से प्रभावित हुए?

If credentials were compromised, report immediately. Do not engage with recovery scammers.

यदि आपने खाता क्रेडेंशियल, व्यक्तिगत या भुगतान जानकारी दर्ज की है, या इस डोमेन से कोई फ़ाइल डाउनलोड की है, तो तुरंत कार्रवाई करें। घटना की रिपोर्ट करने और अपनी सुरक्षा करने में आपकी सहायता के लिए नीचे संसाधन दिए गए हैं।

यूरोपोल
अपने ईयू देश के लिए आधिकारिक रिपोर्टिंग चैनल ढूंढें
National police directory
रिकवरी ठगों से सावधान रहें! अपराधी जांचकर्ता, वकील या रिकवरी एजेंट होने का नाटक करते हुए पीड़ितों से दोबारा संपर्क कर सकते हैं। अग्रिम शुल्क का भुगतान न करें या क्रेडेंशियल साझा न करें। रिकवरी धोखाधड़ी के बारे में और जानें →

अपने स्थानीय अधिकारियों को रिपोर्ट करें

आधिकारिक साइबर अपराध संपर्क, या एक शिकायत ड्राफ्ट बनाएं → प्राप्त करने के लिए अपना देश चुनें।

97-देश निर्देशिका
एआई-सहायता प्राप्त ड्राफ्ट - घटना विवरण एआई प्रदाता द्वारा संसाधित किया जाता है इसकी स्वयं समीक्षा करें और सबमिट करें

किसी भी डोमेन की जाँच करें

संग्रहीत ब्लॉकलिस्ट, WHOIS, DNS और सार्वजनिक स्कैन साक्ष्य का उपयोग करके खतरे का विश्लेषण

अभी स्कैन करें

फ़िशिंग की रिपोर्ट करें

संदिग्ध डोमेन हमारे थ्रेट डेटाबेस में जमा करें — समुदाय की सुरक्षा करें

रिपोर्ट करें

सीधा खतरा फीड

हाल की फ़िशिंग रिपोर्टें और उपलब्धता में परिवर्तन देखे गए

निगरानी करें

जानकारी में रहें, सुरक्षित रहें

लाइव खतरों की निगरानी करें या यदि आपको लगता है कि यह एक गलत सकारात्मक है तो इस लिस्टिंग को चुनौती दें।

सीधा खतरा फीड इस लिस्टिंग के खिलाफ अपील करें
HTML · IFRAME

इस रिपोर्ट को एम्बेड करें

इस थ्रेट इंटेलिजेंस को अपनी वेबसाइट या ब्लॉग पर साझा करें।

embed.html
<iframe
  src="https://phishdestroy.io/hi/embed/domain/smtp-1.coolhair.com.cn"
  title="PhishDestroy threat report for smtp-1.coolhair.com.cn"
  width="100%" height="320"
  loading="lazy"
  referrerpolicy="no-referrer"
  sandbox="allow-same-origin allow-popups allow-popups-to-escape-sandbox"
  style="border:0;border-radius:12px;max-width:100%"
></iframe>