MALICIOUS — CRITICAL
Pemeriksaan phishing dan keamanan gift2gift.cfd
gift2gift[.]
PhishDestroy identifies an active credential theft campaign tied to the domain gift2gift.cfd, currently under investigation with a dynamic risk classification.
- VirusTotal
- 1/92
- Blocklists
- 2 · MetaMask, SEAL
- Ketersediaan
- Terselubung · dapat dijangkau · HTTP 502
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
gift2gift.cfd — Terselubung · dapat dijangkau (HTTP 502). Jenis penipuan: Brand Impersonation. Ringkasan bukti: VirusTotal 1/92 (Gridinsoft); 2 external blocklist matches (MetaMask, SEAL); cloaking observed; PhishDestroy score 78/100. Registrar: Global Domain Group.
Analisis terperinci PhishDestroy AI di bawah tetap berbahasa Inggris untuk menjaga catatan forensik asli.
Evidence Analysis
PhishDestroy identifies an active credential theft campaign tied to the domain gift2gift.cfd, currently under investigation with a dynamic risk classification. This malicious resource masquerades as a reputable gift exchange platform to harvest sensitive login credentials, email addresses, and potentially cryptocurrency wallet access. This domain was flagged during routine threat analysis with the following technical indicators: VirusTotal currently reports zero detections out of 95 scanners, suggesting low antivirus coverage; registration occurred on May 17, 2026 via Global Domain Group LLC; the domain resolves to the IP address 188.114.97.3, which is associated with Let's Encrypt-issued SSL certificates. The infrastructure has not yet been identified on major threat intelligence blocklists such as AlienVault OTX or Abuse.ch URLHaus. Domain reputation scores remain neutral due to its recent creation and limited historical telemetry, increasing the risk of detection evasion. To mitigate exposure to this credential theft campaign, organizations and individuals should block the domain gift2gift.cfd and monitor for any connections to the IP 188.114.97.3 at the network perimeter. Users are advised to enable multi-factor authentication (MFA) on all accounts, avoid entering credentials on unfamiliar domains, and validate any links claiming to offer gift exchange services through official channels. Security teams should deploy DNS filtering rules and inspect historical DNS logs for lateral movement. Given the zero-detection status on VirusTotal, manual verification and user awareness training are critical to prevent successful credential harvesting.
Stored source results
Recorded verdicts and infrastructure observations for this domain.
Cakupan data12 recorded checks
Alur Tanggapan Ancaman Pipeline
Status Daftar Blokir Publik
Tangkapan tersimpan
Intelijen Domain
Rincian teknisDNS, SAN SSL, cap waktu
ZONA SHORTDOT · BUKTI PUBLIK
.cfd
ShortDot zone evidence
ShortDot zone evidence
The linked repository preserves daily zone observations across seven ShortDot-operated TLDs, including registration volume and abuse-related indicators. This registry context is supporting background and is not an independent detection for the domain in this report.
ICANN OVERSIGHT
Akreditasi dan konteks RAA
Akreditasi dan konteks RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Teknologi · 9 identified
Node.js is an open-source, cross-platform, JavaScript runtime environment that executes JavaScript code outside a web browser.
nodejs.org Keyakinan 100%Vue.js is an open-source model–view–viewmodel JavaScript framework for building user interfaces and single-page applications.
vuejs.org Keyakinan 100%Query Migrate is a javascript library that allows you to preserve the compatibility of your jQuery code developed for versions of jQuery older than 1.9.
github.com Keyakinan 100%jQuery CDN is a way to include jQuery in your website without actually downloading and keeping it your website's folder.
code.jquery.com Keyakinan 100%jQuery is a JavaScript library which is a free, open-source software designed to simplify HTML DOM tree traversal and manipulation, as well as event handling, CSS animation, and Ajax.
jquery.com Keyakinan 100%Cloudflare Browser Insights is a tool that measures the performance of websites from the perspective of users.
www.cloudflare.com Keyakinan 100%Cloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com Keyakinan 100%HTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org Keyakinan 100%Analisis VirusTotal
Analisis Performa Situs
Google PageSpeed Insights — mobile performance audit of gift2gift.cfd · checked May 18, 2026
Bukti & Laporan EksternalIndependent lookups and source reports
PD-20260518-843DB7 Recipient: abuse@globaldomaingroup.com Victim safety and official reportingImmediate actions and verified reporting channels
Jika Anda memasukkan kredensial akun, informasi pribadi atau pembayaran, atau mengunduh file dari domain ini, segera ambil tindakan. Di bawah ini adalah sumber daya untuk membantu Anda melaporkan insiden tersebut dan melindungi diri Anda sendiri.
Laporkan kepada Pihak Berwenang di Daerah Anda
Pilih negara Anda untuk mendapatkan kontak resmi kejahatan dunia maya, atau membuat draf pengaduan →.