Notification and current-status evidence
The sent-report ledger records the first outgoing report at .
The recorded recipient is abuse@namecheap.com.
The latest stored availability evidence still shows the domain reachable; 4 months has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
jmper[.]xyz
“Robot Challenge Screen”
jmper.xyz — Belum terverifikasi. Jenis penipuan: Generic Phishing. Ringkasan bukti: VirusTotal 5/91 (alphaMountain.ai, CRDF, Forcepoint ThreatSeeker, Gridinsoft, SOCRadar); 1 external blocklist match (ScamSniffer); PhishDestroy score 78/100. Registrar: Namecheap.
Analisis terperinci PhishDestroy AI di bawah tetap berbahasa Inggris untuk menjaga catatan forensik asli.
Analysis of jmper.xyz indicates a high-risk phishing domain targeting users through a deceptive 'Robot Challenge Screen' page title. The domain was registered on March 26, 2026, via Namecheap and currently resolves to 34.175.18.31, a Google Cloud IP address located in Spain. Infrastructure review shows the site uses Nginx as its web server and is protected by a Let's Encrypt SSL certificate, a common setup for both legitimate and malicious sites. Nameservers point to SiteGround, while MX records route through a third-party spam filtering service, suggesting an attempt to appear operational and legitimate. The domain is actively flagged by two security blocklists and is explicitly blocked by PhishDestroy and ScamSniffer. Five of 94 security vendors on VirusTotal detect the domain as malicious, though the specific payload or phishing kit remains unconfirmed. The HTTP response code is 403 (Forbidden), which may indicate the site is either restricting access, undergoing maintenance, or using anti-bot measures to evade detection. No brand impersonation is evident from the available data, and the exact nature of the phishing scheme—beyond the 'Robot Challenge' theme—is not yet analyzed. Defenders should treat jmper.xyz as an active threat. Block the domain at DNS and network levels, monitor for connections to the associated IP (34.175.18.31), and alert users to avoid interaction. If internal logs show traffic to this domain, investigate for credential theft or malware delivery. Further analysis of the site’s content and payload is recommended to determine the full scope of the campaign.
Alur Tanggapan Ancaman Pipeline
Status Daftar Blokir Publik
Tangkapan tersimpan
Intelijen Domain
Rincian teknisDNS, SAN SSL, cap waktu
ICANN OVERSIGHT
Akreditasi dan konteks RAA
Akreditasi dan konteks RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Teknologi · 1 identified
High-performance HTTP server and reverse proxy, known for stability and low resource usage.
Analisis VirusTotal
Analisis Performa Situs
Google PageSpeed Insights — mobile performance audit of jmper.xyz · checked Jun 26, 2026
Bukti & Laporan Eksternal
PD-20260326-AFE260 Recipient: abuse@namecheap.com Apakah Anda Terpengaruh oleh Situs Ini?
Jika Anda memasukkan kredensial akun, informasi pribadi atau pembayaran, atau mengunduh file dari domain ini, segera ambil tindakan. Di bawah ini adalah sumber daya untuk membantu Anda melaporkan insiden tersebut dan melindungi diri Anda sendiri.
Laporkan kepada Pihak Berwenang di Daerah Anda
Pilih negara Anda untuk mendapatkan kontak resmi kejahatan dunia maya, atau membuat draf pengaduan →.
Periksa Domain Apa Pun
Analisis ancaman menggunakan daftar blokir yang disimpan, WHOIS, DNS, dan bukti pemindaian publik
Pindai SekarangLaporkan Phishing
Laporkan domain yang mencurigakan ke basis data ancaman kami — lindungi komunitas
LaporanPemberitahuan Ancaman Real-Time
Laporan phishing terbaru dan perubahan ketersediaan yang diamati
PantauTetap Terinformasi, Tetap Aman
Pantau ancaman secara langsung atau ajukan keberatan terhadap daftar ini jika Anda yakin ini merupakan false positive