MALICIOUS — CRITICAL
6hcp99[.]com
The domain 6hcp99.com has been assessed as an elevated risk for being a confirmed fake login site, a form of generic phishing.
- VirusTotal
- 16/91
- Blocklists
- No stored match
- Ketersediaan
- Terakhir diketahui aktif · HTTP 200
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Notification and current-status evidence
The sent-report ledger records the first outgoing report at .
The recorded recipient is abuse@xn.net.
The latest stored availability evidence still shows the domain reachable; 7 months has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
Jump to section
6hcp99.com — Terakhir diketahui aktif (HTTP 200). Jenis penipuan: Credential Phishing. Ringkasan bukti: VirusTotal 16/91 (ADMINUSLabs, alphaMountain.ai, BitDefender, Chong Lua Dao, CyRadar); URLQuery 10 alerts; CF Radar malicious; PhishDestroy score 100/100. Registrar: GoDaddy.
Analisis terperinci PhishDestroy AI di bawah tetap berbahasa Inggris untuk menjaga catatan forensik asli.
Evidence Analysis
6hcp99.com: Confirmed Fake Login Site
The domain 6hcp99.com has been assessed as an elevated risk for being a confirmed fake login site, a form of generic phishing.
The domain 6hcp99.com has been assessed as an elevated risk for being a confirmed fake login site, a form of generic phishing. This domain poses a significant threat to users who may be tricked into providing sensitive information such as usernames, passwords, and financial details.
Analysis indicates that 6hcp99.com has been flagged by 22 out of 95 security vendors on VirusTotal, suggesting a moderate to high level of suspicion among the security community. The domain was registered through GoDaddy.com, LLC on June 09, 2018. It resolves to the IP address 103.232.223.36, which is located in Hong Kong and is part of the AS59371 Dimension Network & Communication Limited. The site appears on two security blocklists, PhishDestroy and PhishingDB, further confirming its malicious nature. The SSL certificate associated with the domain is registered to SomeOrganization / VM-0-9-centos, which may indicate a low-level effort to appear legitimate or a compromised server. Despite these findings, the domain is currently offline, which may be a result of takedown efforts by security organizations or the operators themselves.
To mitigate the risks associated with this fake login site, users are advised to remain vigilant and avoid clicking on any links or entering personal information on unfamiliar websites. Organizations should update their security policies to include regular checks for suspicious domain registrations and IP addresses, and employ robust DNS filtering and web protection tools to block access to known phishing sites. Additionally, any users who may have interacted with 6hcp99.com should immediately change their passwords and monitor their accounts for any unauthorized activity. IT teams should also conduct a thorough investigation to ensure that no credentials or sensitive data have been compromised.
Stored source results
Recorded verdicts and infrastructure observations for this domain.
Cakupan data13 recorded checks
Sinyal Keamanan
Intelijen Keamanan Jaringan
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| OpenDNS | 365.505-606-707-808-909.canvbot.cn |
phishing | Phishing Block |
| DNS4EU | 365.505-606-707-808-909.canvbot.cn |
malicious | Sinkholed |
| OpenPhish | 365.505-606-707-808-909.canvbot.cn |
phishing | Phishing - Bet365 |
| Cloudflare DNS | 365.505-606-707-808-909.canvbot.cn |
malicious | Sinkholed |
| DNS0 Zero | 365.505-606-707-808-909.canvbot.cn |
malicious | Sinkholed |
| Cloudflare DNS | 6hcp99.com |
malicious | Sinkholed |
| OpenDNS | 6hcp99.com |
phishing | Phishing Block |
| DigiCert UltraDNS | 6hcp99.com |
malicious | Sinkholed |
| DNS4EU | 6hcp99.com |
malicious | Sinkholed |
| DNS0 Zero | 6hcp99.com |
malicious | Sinkholed |
Alur Tanggapan Ancaman Pipeline
Status Daftar Blokir Publik
Tangkapan tersimpan
Intelijen Domain
Rincian teknisDNS, SAN SSL, cap waktu
ICANN OVERSIGHT
Akreditasi dan konteks RAA
Akreditasi dan konteks RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Teknologi · 1 identified
High-performance HTTP server and reverse proxy, known for stability and low resource usage.
Analisis VirusTotal
Bukti Terarsip
Bukti & Laporan EksternalIndependent lookups and source reports
PD-20260105-9EFE2D Recipient: abuse@xn.net Victim safety and official reportingImmediate actions and verified reporting channels
Jika Anda memasukkan kredensial akun, informasi pribadi atau pembayaran, atau mengunduh file dari domain ini, segera ambil tindakan. Di bawah ini adalah sumber daya untuk membantu Anda melaporkan insiden tersebut dan melindungi diri Anda sendiri.
Laporkan kepada Pihak Berwenang di Daerah Anda
Pilih negara Anda untuk mendapatkan kontak resmi kejahatan dunia maya, atau membuat draf pengaduan →.