Notification and current-status evidence
The sent-report ledger records the first outgoing report at .
The recorded recipient is nicenic@139.com.
The latest stored availability evidence still shows the domain reachable; 6 months has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
casibom-girisadresinn[.]vip
“Hawkins & Clarke | Global Asset Recovery Division”
casibom-girisadresinn.vip — Belum terverifikasi. Jenis penipuan: Generic Phishing. Ringkasan bukti: VirusTotal 7/91 (alphaMountain.ai, Chong Lua Dao, CyRadar, Forcepoint ThreatSeeker, Gridinsoft); PhishDestroy score 78/100. Registrar: NiceNIC.
Analisis terperinci PhishDestroy AI di bawah tetap berbahasa Inggris untuk menjaga catatan forensik asli.
This domain, casibom-girisadresinn.vip, is flagged as a generic phishing site designed to impersonate Hawkins & Clarke, a fictitious global asset recovery division. Analysis indicates the threat actor employed brand impersonation tactics, likely targeting individuals seeking financial or asset recovery services. The page title, Hawkins & Clarke | Global Asset Recovery Division, suggests an attempt to lend credibility to the fraudulent operation, though no legitimate association with the purported entity exists. No evidence of a crypto drainer kit or direct credential harvesting mechanism was observed, but the infrastructure supports high-risk phishing activities. Infrastructure analysis reveals critical technical indicators: the domain resolves to IP address 104.21.86.45 and was registered on February 21, 2026, through NiceNIC International Group Co., Limited. VirusTotal detection metrics show 8 out of 95 security vendors flagging the domain as malicious, while it appears on a single security blocklist. The SSL certificate is issued by Google Trust Services, and the site leverages Cloudflare, HTTP/3, and jsDelivr technologies, which are commonly abused to obfuscate malicious activity. The domain creation date is notably in the future, a red flag indicative of fraudulent registration practices. The domain is currently offline, having been taken down following detection and blocking by security systems. Despite its inactive status, residual risk persists due to the domain's recent registration and the potential for reactivation or migration to a new infrastructure. Users who may have interacted with the site are advised to monitor financial accounts for unauthorized activity and reset credentials for any services accessed during the exposure window. Organizations should update blocklists to include this domain and its associated IP address to prevent future access attempts.
Intelijen Keamanan Jaringan Registrar context
Alur Tanggapan Ancaman Pipeline
Status Daftar Blokir Publik
Tangkapan tersimpan
Intelijen Domain
Rincian teknisDNS, SAN SSL, cap waktu
ICANN OVERSIGHT
Akreditasi dan konteks RAA
Akreditasi dan konteks RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Latest Classified Outcome 2026-08-17 02:41:02 UTC
Teknologi · 3 identified
Free public CDN for open-source projects, serving files from npm and GitHub.
Web infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
Analisis VirusTotal
Bukti Terarsip
Analisis Performa Situs
Google PageSpeed Insights — mobile performance audit of casibom-girisadresinn.vip · checked Jun 26, 2026
Analisis Konfigurasi Situs
Bukti & Laporan Eksternal
PD-20260213-CC5538 Recipient: nicenic@139.com Apakah Anda Terpengaruh oleh Situs Ini?
Jika Anda memasukkan kredensial akun, informasi pribadi atau pembayaran, atau mengunduh file dari domain ini, segera ambil tindakan. Di bawah ini adalah sumber daya untuk membantu Anda melaporkan insiden tersebut dan melindungi diri Anda sendiri.
Laporkan kepada Pihak Berwenang di Daerah Anda
Pilih negara Anda untuk mendapatkan kontak resmi kejahatan dunia maya, atau membuat draf pengaduan →.
Periksa Domain Apa Pun
Analisis ancaman menggunakan daftar blokir yang disimpan, WHOIS, DNS, dan bukti pemindaian publik
Pindai SekarangLaporkan Phishing
Laporkan domain yang mencurigakan ke basis data ancaman kami — lindungi komunitas
LaporanPemberitahuan Ancaman Real-Time
Laporan phishing terbaru dan perubahan ketersediaan yang diamati
PantauTetap Terinformasi, Tetap Aman
Pantau ancaman secara langsung atau ajukan keberatan terhadap daftar ini jika Anda yakin ini merupakan false positive