wjla-tiwaitlf-tiwaitlf-wjla[.]jindunqst[.]com
“域名停靠”
wjla-tiwaitlf-tiwaitlf-wjla.jindunqst.com — असत्यापित. साक्ष्य सारांश: VirusTotal 15/91 (ADMINUSLabs, BitDefender, CRDF, CyRadar, ESET); CF Radar malicious; PhishDestroy score 95/100. रजिस्ट्रार: Gname.
मूल फॉरेंसिक रिकॉर्ड सुरक्षित रखने के लिए नीचे का विस्तृत PhishDestroy AI विश्लेषण अंग्रेज़ी में रखा गया है।
The domain wjla-tiwaitlf-tiwaitlf-wjla.jindunqst.com was created on 24 September 2024 through the registrar Gname.com Pte. Ltd. and is delegated to the Alibaba Cloud DNS servers jm1.alidns.com and jm2.alidns.com. DNS resolution points to the IPv4 address 103.75.15.107, which belongs to AS132839 POWER LINE DATACENTER and is geolocated in Hong Kong. The site does not present an SSL/TLS certificate, meaning it is only reachable over HTTP. The single page that was observed returns the title “域名停靠”, which provides no indication of the intended victim target or malicious functionality. Security monitoring has placed the domain on one blocklist and it is actively blocked by the PhishDestroy service.
Reputation scoring from Gridinsoft rates the domain at 0 out of 100, indicating a complete lack of trust. VirusTotal analysis shows that 15 of 95 scanned security vendors flagged the domain as malicious, reinforcing the suspicion of phishing activity. The domain is currently reported as offline, and no further HTTP response details are available. Based on the available evidence, the infrastructure appears to be a typical short‑lived phishing host that relies on a low‑reputation DNS configuration, a non‑TLS web server, and a Hong Kong‑based hosting provider.
The precise phishing payload, target brand, or credential‑stealing technique has not been observed, leaving the exact attack vector unknown. Defenders should immediately add 103.75.15.107 to network deny lists, enforce blocking of the fully qualified domain name at DNS and proxy layers, and monitor for additional domains that resolve to the same IP or use the same nameservers. Continuous re‑scanning of the domain through multi‑vendor services such as VirusTotal is recommended in case the offline status changes.
नेटवर्क सुरक्षा इंटेलिजेंस
धमकी प्रतिक्रिया पाइपलाइन
सार्वजनिक ब्लॉकलिस्ट स्थिति
सहेजा गया कैप्चर
डोमेन इंटेलिजेंस
तकनीकी विवरणडीएनएस, एसएसएल एसएएन, टाइमस्टैम्प
ICANN OVERSIGHT
Registration: jindunqst.com
प्रत्यायन और आरएए संदर्भ
प्रत्यायन और आरएए संदर्भ
Registrar accreditation and DNS abuse obligations
For the registrable domain jindunqst.com behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
वायरसटोटल विश्लेषण
संग्रहीत साक्ष्य
साक्ष्य और बाहरी रिपोर्टें
क्या आप इस साइट से प्रभावित हुए?
यदि आपने खाता क्रेडेंशियल, व्यक्तिगत या भुगतान जानकारी दर्ज की है, या इस डोमेन से कोई फ़ाइल डाउनलोड की है, तो तुरंत कार्रवाई करें। घटना की रिपोर्ट करने और अपनी सुरक्षा करने में आपकी सहायता के लिए नीचे संसाधन दिए गए हैं।
अपने स्थानीय अधिकारियों को रिपोर्ट करें
आधिकारिक साइबर अपराध संपर्क, या एक शिकायत ड्राफ्ट बनाएं → प्राप्त करने के लिए अपना देश चुनें।
किसी भी डोमेन की जाँच करें
संग्रहीत ब्लॉकलिस्ट, WHOIS, DNS और सार्वजनिक स्कैन साक्ष्य का उपयोग करके खतरे का विश्लेषण
अभी स्कैन करेंफ़िशिंग की रिपोर्ट करें
संदिग्ध डोमेन हमारे थ्रेट डेटाबेस में जमा करें — समुदाय की सुरक्षा करें
रिपोर्ट करेंसीधा खतरा फीड
हाल की फ़िशिंग रिपोर्टें और उपलब्धता में परिवर्तन देखे गए
निगरानी करेंजानकारी में रहें, सुरक्षित रहें
लाइव खतरों की निगरानी करें या यदि आपको लगता है कि यह एक गलत सकारात्मक है तो इस लिस्टिंग को चुनौती दें।