Notification and current-status evidence
The sent-report ledger records the first outgoing report at .
The recorded recipient is abuse@globaldomaingroup.com.
The latest stored availability evidence still shows the domain reachable; 6 months has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
user1705[.]trustpay[.]ac
“Aura Pay l Crypto Card without KYC”
user1705.trustpay.ac — असत्यापित. साक्ष्य सारांश: VirusTotal 2/93 (Gridinsoft, SOCRadar); 1 external blocklist match (ScamSniffer); PhishDestroy score 71/100. रजिस्ट्रार: Global Domain Group.
मूल फॉरेंसिक रिकॉर्ड सुरक्षित रखने के लिए नीचे का विस्तृत PhishDestroy AI विश्लेषण अंग्रेज़ी में रखा गया है।
Analysis of user1705.trustpay.ac indicates a newly registered domain employed for a generic phishing campaign targeting users of the “Aura Pay” service. The domain was created on 21 February 2026 and is hosted on Cloudflare infrastructure (AS13335) with the resolved address 104.21.69.139 located in the United States. The site presented the page title “Aura Pay l Crypto Card without KYC”, suggesting an attempt to lure victims into providing personal or financial information under the pretense of a cryptocurrency card offering that ostensibly does not require Know‑Your‑Customer verification. The TLS certificate is issued by Google Trust Services under the WE1 intermediate, confirming that HTTPS was correctly configured at the time of observation. HTTP traffic returned a 404 status code, and the service was identified as using Cloudflare Browser Insights, Cloudflare edge services, and HTTP/3.
The domain is currently taken offline, and its hosting provider’s nameservers (karl.ns.cloudflare.com, margot.ns.cloudflare.com) remain active. Security telemetry shows that two of ninety‑three VirusTotal scanners flagged the domain, and it appears on two external blocklists. Both PhishDestroy and ScamSniffer have added the domain to their phishing blocklists, reinforcing the assessment of malicious intent. Registration was performed through Global Domain Group LLC, a registrar that does not appear to have issued any public warnings regarding this domain.
Given the limited visibility of the actual content, the primary evidence consists of metadata, certificate details, and the page title. Defenders should continue to block the domain and its associated IP address, monitor for any reactivation, and include the domain in URL filtering policies. Adding the IP 104.21.69.139 to network‑level deny lists may mitigate collateral abuse originating from the same Cloudflare edge.
धमकी प्रतिक्रिया पाइपलाइन
सार्वजनिक ब्लॉकलिस्ट स्थिति
तकनीकें · 3 identified
Cloudflare Browser Insights is a tool that measures the performance of websites from the perspective of users.
www.cloudflare.com 100% विश्वासCloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com 100% विश्वासHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100% विश्वासवायरसटोटल विश्लेषण
संग्रहीत साक्ष्य
साइट कॉन्फ़िगरेशन विश्लेषण
साक्ष्य और बाहरी रिपोर्टें
PD-20260203-040832 Recipient: abuse@globaldomaingroup.com क्या आप इस साइट से प्रभावित हुए?
यदि आपने खाता क्रेडेंशियल, व्यक्तिगत या भुगतान जानकारी दर्ज की है, या इस डोमेन से कोई फ़ाइल डाउनलोड की है, तो तुरंत कार्रवाई करें। घटना की रिपोर्ट करने और अपनी सुरक्षा करने में आपकी सहायता के लिए नीचे संसाधन दिए गए हैं।
अपने स्थानीय अधिकारियों को रिपोर्ट करें
आधिकारिक साइबर अपराध संपर्क, या एक शिकायत ड्राफ्ट बनाएं → प्राप्त करने के लिए अपना देश चुनें।
किसी भी डोमेन की जाँच करें
संग्रहीत ब्लॉकलिस्ट, WHOIS, DNS और सार्वजनिक स्कैन साक्ष्य का उपयोग करके खतरे का विश्लेषण
अभी स्कैन करेंफ़िशिंग की रिपोर्ट करें
संदिग्ध डोमेन हमारे थ्रेट डेटाबेस में जमा करें — समुदाय की सुरक्षा करें
रिपोर्ट करेंसीधा खतरा फीड
हाल की फ़िशिंग रिपोर्टें और उपलब्धता में परिवर्तन देखे गए
निगरानी करेंजानकारी में रहें, सुरक्षित रहें
लाइव खतरों की निगरानी करें या यदि आपको लगता है कि यह एक गलत सकारात्मक है तो इस लिस्टिंग को चुनौती दें।