web[.]quocanh[.]ceo
“Fakebill LePhanQuocAnh - Công cụ fake bill chuyển khoản dùng để seeding”
web.quocanh.ceo — सामग्री अनुपलब्ध (HTTP 502). ब्रांड प्रतिरूपण: Telegram; घोटाले का प्रकार: Brand Impersonation. साक्ष्य सारांश: VirusTotal 3/95 (alphaMountain.ai, Gridinsoft, SOCRadar); PhishDestroy score 65/100. रजिस्ट्रार: CSL Computer Service L….
मूल फॉरेंसिक रिकॉर्ड सुरक्षित रखने के लिए नीचे का विस्तृत PhishDestroy AI विश्लेषण अंग्रेज़ी में रखा गया है।
The domain web.quocanh.ceo was observed hosting a Telegram brand‑impersonation site. The page title returned by the server reads “Fakebill LePhanQuocAnh – Công cụ fake bill chuyển khoản dùng để seeding,” indicating a fake‑bill generation tool that may have been used to lure victims. The domain was registered on September 4 2025 through CSL Computer Service Langenbach GmbH d/b/a joker.com and is resolved to the Cloudflare edge address 172.67.148.222, belonging to ASN 13335 (Cloudflare, Inc.) located in the United States. DNS resolution uses the Cloudflare name servers ajay.ns.cloudflare.com and stevie.ns.cloudflare.com.
No SSL certificate is presented, and the site currently returns an offline HTTP status, confirming that the malicious content has been taken down. Reputation checks show a Gridinsoft trust score of 0 / 100 and the domain appears on one security blocklist. VirusTotal analysis recorded three positive detections out of ninety‑five scanners. PhishDestroy has also blocked the domain.
The risk rating is elevated, reflecting the targeted impersonation of the Telegram brand. While the offline status limits immediate exposure, the infrastructure details—Cloudflare hosting, low trust score, and presence on blocklists—suggest that the operators may reuse the same hosting configuration for future campaigns. Defenders should add the domain and its associated IP address to block lists, monitor for any re‑registration or resurrection of the site, and watch for similar page‑title patterns in future traffic. Continuous ingestion of feeds that reference the Cloudflare name servers and the registrar joker.com can help detect related infrastructure early.
धमकी प्रतिक्रिया पाइपलाइन
सार्वजनिक ब्लॉकलिस्ट स्थिति
सहेजा गया कैप्चर
डोमेन इंटेलिजेंस
तकनीकी विवरणडीएनएस, एसएसएल एसएएन, टाइमस्टैम्प
ICANN OVERSIGHT
Registration: quocanh.ceo
प्रत्यायन और आरएए संदर्भ
प्रत्यायन और आरएए संदर्भ
Registrar accreditation and DNS abuse obligations
For the registrable domain quocanh.ceo behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
वायरसटोटल विश्लेषण
साक्ष्य और बाहरी रिपोर्टें
क्या आप इस साइट से प्रभावित हुए?
यदि आपने खाता क्रेडेंशियल, व्यक्तिगत या भुगतान जानकारी दर्ज की है, या इस डोमेन से कोई फ़ाइल डाउनलोड की है, तो तुरंत कार्रवाई करें। घटना की रिपोर्ट करने और अपनी सुरक्षा करने में आपकी सहायता के लिए नीचे संसाधन दिए गए हैं।
अपने स्थानीय अधिकारियों को रिपोर्ट करें
आधिकारिक साइबर अपराध संपर्क, या एक शिकायत ड्राफ्ट बनाएं → प्राप्त करने के लिए अपना देश चुनें।
किसी भी डोमेन की जाँच करें
संग्रहीत ब्लॉकलिस्ट, WHOIS, DNS और सार्वजनिक स्कैन साक्ष्य का उपयोग करके खतरे का विश्लेषण
अभी स्कैन करेंफ़िशिंग की रिपोर्ट करें
संदिग्ध डोमेन हमारे थ्रेट डेटाबेस में जमा करें — समुदाय की सुरक्षा करें
रिपोर्ट करेंसीधा खतरा फीड
हाल की फ़िशिंग रिपोर्टें और उपलब्धता में परिवर्तन देखे गए
निगरानी करेंजानकारी में रहें, सुरक्षित रहें
लाइव खतरों की निगरानी करें या यदि आपको लगता है कि यह एक गलत सकारात्मक है तो इस लिस्टिंग को चुनौती दें।