सुरक्षा रिपोर्ट पर जाएँ
⚠️
इस डोमेन को दुर्भावनापूर्ण के रूप में चिह्नित किया गया है।
सुरक्षा इंजन एक पहचान की रिपोर्ट कर रहे हैं: 20। अत्यधिक सावधानी बरतें - क्रेडेंशियल या व्यक्तिगत जानकारी दर्ज न करें।
डोमेन सुरक्षा और ख़तरे की आसूचना

toehhfw[.]shop

“Messenger”

धमकी भरा फैसला गंभीर 100/100 साक्ष्य स्कोर
उपलब्धता असत्यापित वर्तमान पहुंच योग्यता असत्यापित है
वायरस का कुल पता लगाना: 20/91 Spamhaus DBL: DBL_SPAM घोटाले का प्रकार: Generic Phishing
OTX: 2 refs 03/07/2026

साक्ष्य सारांश

आलोचनात्मक
Evidence score
100/100

Analysis of the domain toehhfw.shop indicates active phishing infrastructure targeting users of the Messenger platform. Registered through Nicenic International Group Co., Limited, the domain resolves to the IP address 27.124.47.186, hosted under Rackip Consultancy Pte. LTD in Hong Kong. Infrastructure analysis reveals nameservers ns3.my-nddns.com and ns4.my-nddns.com, which are consistent with previously observed phishing campaigns. The SSL certificate is issued for Telegram and a wildcard *.local domain, suggesting an attempt to lend legitimacy to the fraudulent site, though the page title explicitly displays 'Messenger,' aligning with the impersonation target. The domain appears on one security blocklist and has been flagged by 20 of 91 security vendors in VirusTotal, with PhishDestroy currently blocking access. AlienVault OTX reports the domain in two threat intelligence pulses, further corroborating its malicious classification. Google Safe Browsing has flagged the site for social engineering, a designation typically applied to pages designed to deceive users into divulging credentials or sensitive information. The HTTP status code 200 confirms the site is operational as of the report date, posing an ongoing risk. Defenders should treat this domain as high-risk and implement blocking measures at the network and endpoint levels. Given the use of known phishing nameservers and a hosting provider associated with malicious activity, organizations are advised to monitor for connections to 27.124.47.186 and related infrastructure. The exact content of the phishing page remains unanalyzed, but the combination of technical indicators and detection counts strongly supports its classification as a credential-harvesting site. No evidence suggests a broader campaign beyond this domain, though further correlation with other domains using the same nameservers or registrar may reveal additional threats.

VirusTotal
VirusTotal
20 det.
OTX references
सीएफ रडार
दुर्भावनापूर्ण
TLS प्रमाणपत्र
समाप्त या असत्यापित
देखी गई स्थिति
असत्यापित
PhishDestroy
विनाश सूची
सूचीबद्ध

Data Coverage

VirusTotal 20 / 91 यूआरएलक्वेरी जाँच नहीं की गई फ़िशस्टैट्स जाँच नहीं की गई ओटीएक्स 2 community references सीएफ रडार provider verdict: malicious URLScan capture not submitted URLScan verdict निष्कर्ष उपलब्ध नहीं डीएनएस ब्लॉक जाँच नहीं की गई TLS समाप्त या असत्यापित कौन है not parsed स्क्रीनशॉट कैद नहीं हुआ चेन पुनर्निर्देशित करें जांच नहीं की गई
नेटवर्क सुरक्षा इंटेलिजेंसRegistrar context
CF Cloudflare Radar Verdict दुर्भावनापूर्ण
Phishing
Registrar context NiceNIC
Stored registration data identifies NICENIC INTERNATIONAL GROUP CO., LIMITED (IANA 3765) as the registrar. PhishDestroy maintains separate NiceNIC abuse-report research; registrar association is contextual and is not an independent detection for this domain.
NiceNIC Verdict Full Investigation
SSL Certificate Invalid
SSL certificate is invalid or expired. Issuer: Telegram

धमकी प्रतिक्रिया पाइपलाइन

खोज
Checks
Reports
उपलब्धता
9/11

ब्लॉकलिस्ट कवरेज

10 निगरानी वाले बाहरी स्रोत · संग्रहीत स्नैपशॉट 13/08/2026

10 निगरानी वाले बाहरी स्रोत कोई मिलान नहीं

डोमेन इंटेलिजेंस

डोमेन
गूगल सुरक्षित ब्राउज़िंग ध्वजांकित Social engineering checked 20/07/2026
सर्वर / ASN nginx/1.18.0 (Ubuntu) · AS152194 CTG Server Limited
IP प्रतिष्ठा IP abuse confidence 0/100 0 reports checked 19/07/2026
रजिस्ट्रार Nicenic RU(RU) PhishDestroy Investigation
IP पता 27.124.47.186 HK
भौगोलिक स्थानHK Sheung Wan, HK
नेटवर्कAS152194 · Rackip Consultancy Pte. LTD
रिवर्स IPviewdns.info → rapiddns.io →
तकनीकी विवरणDNS, TLS नाम और समय-मुद्राएँ
पहली बार पता चला03/07/2026
नेमसर्वरns4.my-ndns.com
TLS फिंगरप्रिंट
TLS अवलोकन12/06/2026 से मान्य19/07/2026 को स्कैन किया गया
Favicon Hash
पेज शीर्षक
Messenger
TLS प्रमाणपत्र
समाप्त या असत्यापित · जारीकर्ता Telegram · valid for 787 days
ICANN OVERSIGHT

प्रत्यायन और आरएए संदर्भ

Registrar accreditation and DNS abuse obligations

For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.

Accreditation is a contract, not a safety certification.

RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.

मान्यता एक अनुबंध है, सुरक्षा की मुहर नहीं। ICANN शुल्क सत्यापित करें RAA §3.18 पढ़ें PHISHDESTROY INVESTIGATIONICANN funding, contracts, and DNS abuse oversight
Accountability draft कुछ भी अपने आप नहीं भेजा जाता।
इस डोमेन की रिपोर्ट करें सबूत जमा करें और दूसरों की सुरक्षा में मदद करें

वायरसटोटल विश्लेषण

20 / 91 सुरक्षा विक्रेताओं ने इस डोमेन को चिह्नित किया
View on VT
Last analyzed First positive detection
alphaMountain.ai
BitDefender
Chong Lua Dao
CRDF
साइरेडार
ईएसईटी
Emsisoft
Forcepoint ThreatSeeker
Fortinet
G-Data
गूगल सुरक्षित ब्राउज़िंग
Gridinsoft
कास्परस्की
LevelBlue
Lionic
नेटक्राफ्ट
SOCRadar
सोफोस
VIPRE
वेबरूट

क्या आप इस साइट से प्रभावित हुए?

If credentials were compromised, report immediately. Do not engage with recovery scammers.

यदि आपने खाता क्रेडेंशियल, व्यक्तिगत या भुगतान जानकारी दर्ज की है, या इस डोमेन से कोई फ़ाइल डाउनलोड की है, तो तुरंत कार्रवाई करें। घटना की रिपोर्ट करने और अपनी सुरक्षा करने में आपकी सहायता के लिए नीचे संसाधन दिए गए हैं।

यूरोपोल
अपने ईयू देश के लिए आधिकारिक रिपोर्टिंग चैनल ढूंढें
National police directory
रिकवरी ठगों से सावधान रहें! अपराधी जांचकर्ता, वकील या रिकवरी एजेंट होने का नाटक करते हुए पीड़ितों से दोबारा संपर्क कर सकते हैं। अग्रिम शुल्क का भुगतान न करें या क्रेडेंशियल साझा न करें। रिकवरी धोखाधड़ी के बारे में और जानें →

अपने स्थानीय अधिकारियों को रिपोर्ट करें

आधिकारिक साइबर अपराध संपर्क, या एक शिकायत ड्राफ्ट बनाएं → प्राप्त करने के लिए अपना देश चुनें।

97-देश निर्देशिका
एआई-सहायता प्राप्त ड्राफ्ट - घटना विवरण एआई प्रदाता द्वारा संसाधित किया जाता है इसकी स्वयं समीक्षा करें और सबमिट करें

किसी भी डोमेन की जाँच करें

संग्रहीत ब्लॉकलिस्ट, WHOIS, DNS और सार्वजनिक स्कैन साक्ष्य का उपयोग करके खतरे का विश्लेषण

अभी स्कैन करें

फ़िशिंग की रिपोर्ट करें

संदिग्ध डोमेन हमारे थ्रेट डेटाबेस में जमा करें — समुदाय की सुरक्षा करें

रिपोर्ट करें

सीधा खतरा फीड

हाल की फ़िशिंग रिपोर्टें और उपलब्धता में परिवर्तन देखे गए

निगरानी करें

जानकारी में रहें, सुरक्षित रहें

लाइव खतरों की निगरानी करें या यदि आपको लगता है कि यह एक गलत सकारात्मक है तो इस लिस्टिंग को चुनौती दें।

सीधा खतरा फीड इस लिस्टिंग के खिलाफ अपील करें

बाहरी उपकरण

HTML · IFRAME

इस रिपोर्ट को एम्बेड करें

इस थ्रेट इंटेलिजेंस को अपनी वेबसाइट या ब्लॉग पर साझा करें।

embed.html
<iframe
  src="https://phishdestroy.io/hi/embed/domain/toehhfw.shop"
  title="PhishDestroy threat report for toehhfw.shop"
  width="100%" height="320"
  loading="lazy"
  referrerpolicy="no-referrer"
  sandbox="allow-same-origin allow-popups allow-popups-to-escape-sandbox"
  style="border:0;border-radius:12px;max-width:100%"
></iframe>

एक अत्यंत सच्चा धन्यवाद-पत्र

व्यंग्यात्मक मसौदा जनरेटर

प्राप्तकर्ता
शुल्क संदर्भ

यह व्यंग्यात्मक मसौदा है। शुल्क के आंकड़े अनुमान हैं; इन्हें इस डोमेन से ठीक-ठीक जोड़ने का दावा नहीं किया जाता।