echo-preview[.]daikirai[.]com
Pemeriksaan phishing dan keamanan echo-preview.daikirai.com
“Echo”
echo-preview.daikirai.com — Terakhir diketahui aktif (HTTP 200). Jenis penipuan: Generic Phishing. Ringkasan bukti: VirusTotal 3/91 (CRDF, Gridinsoft, SOCRadar); 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 76/100. Registrar: Cloudflare.
Analisis terperinci PhishDestroy AI di bawah tetap berbahasa Inggris untuk menjaga catatan forensik asli.
Evidence Analysis
This domain, echo-preview.daikirai.com, is flagged as an active high-risk phishing site targeting users of Echo-related services. Infrastructure analysis reveals the domain was registered on May 11, 2026, through Cloudflare, Inc., and currently resolves to the IP address 104.21.5.79, located in Canada. The domain is served by Cloudflare nameservers julio.ns.cloudflare.com and stella.ns.cloudflare.com, a common pattern observed in phishing campaigns leveraging Cloudflare’s infrastructure to obscure origin servers and evade detection. The domain appears on three security blocklists and is actively blocked by multiple threat intelligence feeds, including PhishDestroy, MetaMask, and SEAL. Despite these detections, the domain has not yet been flagged by VirusTotal, with 0 out of 95 engines reporting malicious activity as of July 12, 2026. The page title, 'Echo,' suggests an attempt to mimic legitimate Echo services, though the exact content and targeting method remain unconfirmed due to the absence of deeper forensic analysis. The domain’s SSL certificate is issued by Google Trust Services, providing a superficial layer of legitimacy while failing to mitigate the underlying threat. Defenders should treat this domain as actively malicious based on its presence on multiple blocklists and its association with known phishing infrastructure. The HTTP status code 200 indicates the site is operational, and the lack of detections in VirusTotal should not be interpreted as a sign of safety, given the domain’s inclusion in other reputable threat feeds. Network-level blocking is recommended for all endpoints, and security teams should monitor for connections to 104.21.5.79 or related subdomains under daikirai.com. Further investigation into the domain’s hosting environment and potential ties to broader phishing campaigns is advised, particularly given its recent registration and use of Cloudflare’s proxy services.
Cakupan data12 recorded checks
Alur Tanggapan Ancaman Pipeline
Status Daftar Blokir Publik
Intelijen Domain
Rincian teknisDNS, SAN SSL, cap waktu
ICANN OVERSIGHT
Registration: daikirai.com
Akreditasi dan konteks RAA
Akreditasi dan konteks RAA
Registrar accreditation and DNS abuse obligations
For the registrable domain daikirai.com behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Analisis VirusTotal
Bukti & Laporan EksternalIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
Jika Anda memasukkan kredensial akun, informasi pribadi atau pembayaran, atau mengunduh file dari domain ini, segera ambil tindakan. Di bawah ini adalah sumber daya untuk membantu Anda melaporkan insiden tersebut dan melindungi diri Anda sendiri.
Laporkan kepada Pihak Berwenang di Daerah Anda
Pilih negara Anda untuk mendapatkan kontak resmi kejahatan dunia maya, atau membuat draf pengaduan →.