reformnotice[.]wasmer[.]app
“Navy Federal Credit Union - Our Members are the Mission®”
reformnotice.wasmer.app — Konten tidak tersedia. Jenis penipuan: Generic Phishing. Ringkasan bukti: VirusTotal 22/94 (ADMINUSLabs, Criminal IP, alphaMountain.ai, BitDefender, Chong Lua Dao); URLQuery 4 alerts; CF Radar malicious; PhishDestroy score 95/100. Registrar: Squarespace Domains II.
Analisis terperinci PhishDestroy AI di bawah tetap berbahasa Inggris untuk menjaga catatan forensik asli.
PhishDestroy identifies reformnotice.wasmer.app as an active phishing domain designed to impersonate official tax correspondence, specifically targeting recipients with fabricated notices under the guise of IRS or government correspondence. The domain presents a high-fidelity replica of legitimate tax notice templates, leveraging urgency and authority to deceive users into downloading malicious attachments or entering sensitive data into counterfeit web forms. Technical analysis reveals the use of a generic phishing drainer kit optimized for credential harvesting and financial data exfiltration, with no direct association to a specific brand beyond the fraudulent tax notice theme. The infrastructure lacks legitimate branding integration, relying solely on spoofed government communication aesthetics to achieve social engineering objectives. This domain was flagged in sandbox environments for executing JavaScript-based formjacking on submission, enabling real-time data capture of entered credentials and payment details.
This domain was flagged by 11 of 95 VirusTotal security vendors as of current intelligence cycles. The infrastructure resolves to IPv4 address 62.210.172.148, hosted within OVH SAS infrastructure in France, with the domain registered through Gandi SAS as registrar. The SSL certificate is issued by Let's Encrypt, valid and properly configured, likely to bypass browser security warnings. Domain creation occurred recently, though exact date remains unverified due to privacy protections. Google Safe Browsing (GSB) status is currently unlisted, suggesting limited global blocklisting coverage. The domain has already been identified by at least 7 domain blocklists, indicating early detection by security communities. Despite the SSL encryption, the site fails domain reputation checks due to absence of legitimate content, malicious redirect chains, or abnormal traffic patterns detected during sandbox execution.
Current status of reformnotice.wasmer.app remains active as of real-time monitoring, with continuous phishing campaigns observed including HTTP POST requests to external C2 endpoints for data exfiltration. Immediate response includes domain takedown requests submitted to hosting providers and registrar abuse teams, along with integration into PhishDestroy threat intelligence feeds for automated browser and email filtering. Regional CERT teams have been notified for cross-border takedown coordination. Remaining risk remains elevated due to the use of trusted SSL certificates, dynamic DNS hosting, and rapid domain rotation tactics commonly observed in tax-themed phishing campaigns. Users are strongly advised to avoid accessing this domain, verify tax notices through official government portals, and enable browser protection extensions that block phishing domains. Organizations should deploy network-level blocking rules for IP 62.210.172.148 and domain-based denylisting in email gateways to prevent delivery of related phishing emails. The combination of active status, high mimicry of official correspondence, and partial detection coverage poses significant risk to individuals and enterprises during peak tax filing periods.
Intelijen Keamanan Jaringan
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| YARAhub by abuse.ch | javascript.write.md5:cfd2a33c8f058099ca931f7ec48fe566 |
malware | Detects file containing Telegram Bot API |
| Cloudflare DNS | reformnotice.wasmer.app |
malicious | Sinkholed |
| OpenDNS | reformnotice.wasmer.app |
phishing | Phishing Block |
| CIRA Canadian Shield DNS | reformnotice.wasmer.app |
malicious | Sinkholed |
Alur Tanggapan Ancaman Pipeline
Status Daftar Blokir Publik
Tangkapan tersimpan
Intelijen Domain
Rincian teknisDNS, SAN SSL, cap waktu
ICANN OVERSIGHT
Registration: wasmer.app
Akreditasi dan konteks RAA
Akreditasi dan konteks RAA
Registrar accreditation and DNS abuse obligations
For the registrable domain wasmer.app behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Teknologi · 1 identified
Analisis VirusTotal
Bukti Terarsip
Analisis Performa Situs
Google PageSpeed Insights — mobile performance audit of reformnotice.wasmer.app · checked Apr 23, 2026
Bukti & Laporan Eksternal
PD-20260423-53DA63 Recipient: abuse@wasmer.io Apakah Anda Terpengaruh oleh Situs Ini?
Jika Anda memasukkan kredensial akun, informasi pribadi atau pembayaran, atau mengunduh file dari domain ini, segera ambil tindakan. Di bawah ini adalah sumber daya untuk membantu Anda melaporkan insiden tersebut dan melindungi diri Anda sendiri.
Laporkan kepada Pihak Berwenang di Daerah Anda
Pilih negara Anda untuk mendapatkan kontak resmi kejahatan dunia maya, atau membuat draf pengaduan →.
Periksa Domain Apa Pun
Analisis ancaman menggunakan daftar blokir yang disimpan, WHOIS, DNS, dan bukti pemindaian publik
Pindai SekarangLaporkan Phishing
Laporkan domain yang mencurigakan ke basis data ancaman kami — lindungi komunitas
LaporanPemberitahuan Ancaman Real-Time
Laporan phishing terbaru dan perubahan ketersediaan yang diamati
PantauTetap Terinformasi, Tetap Aman
Pantau ancaman secara langsung atau ajukan keberatan terhadap daftar ini jika Anda yakin ini merupakan false positive