Notification and current-status evidence
The sent-report ledger records the first outgoing report at .
The recorded recipient is abuse@cosmotown.com.
The latest stored availability evidence still shows the domain reachable; 5 months has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
yyyyyyykjghfghjkjlhjnkjhgfhfjgkhghfg[.]com
“The United States Social Security Administration | SSA”
yyyyyyykjghfghjkjlhjnkjhgfhfjgkhghfg.com — असत्यापित. ब्रांड प्रतिरूपण: Govus; घोटाले का प्रकार: Generic Phishing. साक्ष्य सारांश: VirusTotal 11/91 (alphaMountain.ai, BitDefender, Chong Lua Dao, Forcepoint ThreatSeeker, Fortinet); URLQuery 6 alerts; URLScan malicious verdict; CF Radar malicious; PhishDestroy score 95/100. रजिस्ट्रार: TuringSign.
मूल फॉरेंसिक रिकॉर्ड सुरक्षित रखने के लिए नीचे का विस्तृत PhishDestroy AI विश्लेषण अंग्रेज़ी में रखा गया है।
The domain yyyyyyykjghfghjkjlhjnkjhgfhfjgkhghfg.com has been identified as a brand impersonation threat specifically targeting the United States Social Security Administration (SSA). This domain is currently offline, having been taken down after its malicious nature was confirmed. The site was designed to mimic the official SSA website in order to harvest visitors' personal information and credentials, representing a classic credential theft scheme.
Technical analysis reveals that this domain was flagged by 2 out of 95 VirusTotal security vendors, indicating some initial detection but not widespread recognition. It was registered through TuringSign Inc. d/b/a Cosmotown and created on March 11, 2026, with an IP address of 192.142.54.88. The SSL certificate was issued by Let's Encrypt (R13), which is a free certificate authority often abused by malicious actors. The domain appears on 1 security blocklist, suggesting limited but present blocking measures. The page title, "The United States Social Security Administration | SSA," further confirms the impersonation attempt.
Given that this domain is now offline, the immediate threat has been neutralized. However, users should remain vigilant as similar domains may appear. It is recommended to always verify the legitimacy of any website claiming to be a government agency by checking the official URL directly. Avoid clicking on links in unsolicited emails or messages. If you have already entered any personal information on this site, consider monitoring your accounts for suspicious activity and reporting the incident to the appropriate authorities.
नेटवर्क सुरक्षा इंटेलिजेंस
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| YARAhub by abuse.ch | yyyyyyykjghfghjkjlhjnkjhgfhfjgkhghfg.com/ |
malware | Detects file containing Telegram Bot API |
| YARAhub by abuse.ch | download2279.mediafire.com/5rk46jmcwf8gfkahcvqshbqbi_ucpuxz7jmczzow8cdp3qatkejr2rhqkogyghbumdradothv5nhymjjfluudseistt8lizsbkzpb5xouo_lpyz7d650j7oago7xesldc4i4fdih-wbdneyvb9nkugqvkjgi8tqnqgxgmlnddxk0/jojq868tzjw1ry2/ssa_e-file.vbs |
malware | Detect files disabling or modifying Windows Defender, Windows Firewall, or Microsoft Smartscreen |
| DigiCert UltraDNS | www.mediafire.com |
malicious | Sinkholed |
| DigiCert UltraDNS | download2279.mediafire.com |
malicious | Sinkholed |
| Hagezi Threat Feed | yyyyyyykjghfghjkjlhjnkjhgfhfjgkhghfg.com |
malicious | Sinkholed |
| DNS4EU | yyyyyyykjghfghjkjlhjnkjhgfhfjgkhghfg.com |
malicious | Sinkholed |
धमकी प्रतिक्रिया पाइपलाइन
सार्वजनिक ब्लॉकलिस्ट स्थिति
सहेजा गया कैप्चर
डोमेन इंटेलिजेंस
तकनीकी विवरणडीएनएस, एसएसएल एसएएन, टाइमस्टैम्प
ICANN OVERSIGHT
प्रत्यायन और आरएए संदर्भ
प्रत्यायन और आरएए संदर्भ
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
तकनीकें · 2 identified
High-performance web server compatible with Apache configurations.
Third major version of HTTP protocol, built on QUIC for faster, more reliable connections.
वायरसटोटल विश्लेषण
साइट प्रदर्शन विश्लेषण
Google PageSpeed Insights — mobile performance audit of yyyyyyykjghfghjkjlhjnkjhgfhfjgkhghfg.com · checked Mar 11, 2026
साक्ष्य और बाहरी रिपोर्टें
PD-20260311-FD248D Recipient: abuse@cosmotown.com क्या आप इस साइट से प्रभावित हुए?
यदि आपने खाता क्रेडेंशियल, व्यक्तिगत या भुगतान जानकारी दर्ज की है, या इस डोमेन से कोई फ़ाइल डाउनलोड की है, तो तुरंत कार्रवाई करें। घटना की रिपोर्ट करने और अपनी सुरक्षा करने में आपकी सहायता के लिए नीचे संसाधन दिए गए हैं।
अपने स्थानीय अधिकारियों को रिपोर्ट करें
आधिकारिक साइबर अपराध संपर्क, या एक शिकायत ड्राफ्ट बनाएं → प्राप्त करने के लिए अपना देश चुनें।
किसी भी डोमेन की जाँच करें
संग्रहीत ब्लॉकलिस्ट, WHOIS, DNS और सार्वजनिक स्कैन साक्ष्य का उपयोग करके खतरे का विश्लेषण
अभी स्कैन करेंफ़िशिंग की रिपोर्ट करें
संदिग्ध डोमेन हमारे थ्रेट डेटाबेस में जमा करें — समुदाय की सुरक्षा करें
रिपोर्ट करेंसीधा खतरा फीड
हाल की फ़िशिंग रिपोर्टें और उपलब्धता में परिवर्तन देखे गए
निगरानी करेंजानकारी में रहें, सुरक्षित रहें
लाइव खतरों की निगरानी करें या यदि आपको लगता है कि यह एक गलत सकारात्मक है तो इस लिस्टिंग को चुनौती दें।