Notification and current-status evidence
The sent-report ledger records the first outgoing report at .
The recorded recipient is xx1315aas@163.com.
The latest stored availability evidence still shows the domain reachable; 16 days has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
aa-deepseek[.]com[.]cn
“DeepSeek | ä¸ä¸ä»£ AI åºç¡è®¾æ½ â 1M ä¸ä¸ææè°å¤§æ¨¡å”
aa-deepseek.com.cn — Non verificato. Riepilogo delle prove: VirusTotal 10/91 (alphaMountain.ai, Antiy-AVL, BitDefender, CRDF, Forcepoint ThreatSeeker); URLQuery 1 alert; Spamhaus DBL_SPAM; PhishDestroy score 88/100. Registrar: 北京新网数码信息技术有限公司.
L’analisi dettagliata di PhishDestroy AI resta in inglese per preservare il rapporto forense originale.
On July 24, 2026, analysts observed that the domain aa-deepseek.com.cn was registered on July 01, 2026 through the registrar 北京新网数码信息技术有限公司. The domain resolves to the single IP address 204.194.55.128 and is served by the nameservers ns1.julydns.com, ns2.julydns.com, ns1.onclouddns.com, and ns2.onclouddns.com. Threat intelligence categorises the site as a generic phishing operation and assigns a high risk level.
The domain appears on one public security blocklist and is actively blocked by the PhishDestroy service. VirusTotal analysis shows that three of ninety‑one scanning engines returned a detection, indicating that at least a minority of vendors have identified malicious behavior. No additional public indicators such as SSL certificate details, HTTP response codes, or page title have been disclosed, leaving the exact content of the site unverified.
Nevertheless, the combination of recent creation, dedicated phishing‑oriented registrar, single‑host infrastructure, and existing blocklist entries supports the conclusion that the domain is being used for credential‑ harvesting or related fraudulent activity. Defenders are advised to add aa‑deepseek.com.cn and its resolved IP 204.194.55.128 to outbound and inbound filtering rules, monitor for any DNS queries to the listed nameservers, and ensure that any detection alerts referencing this domain are escalated according to high‑severity incident response procedures. Continuous re‑evaluation is recommended in case additional detections appear in future VirusTotal or other threat feeds.
Informazioni sulla sicurezza di rete
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DNS4EU | aa-deepseek.com.cn |
malicious | Sinkholed |
Pipeline di risposta alle minacce
Stato della lista di blocco pubblica
Tecnologie · 3 identified
Nginx is a web server that can also be used as a reverse proxy, load balancer, mail proxy and HTTP cache.
nginx.org Confidenza al 100%HTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org Confidenza al 100%HTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org Confidenza al 100%Analisi di VirusTotal
Analisi delle prestazioni del sito
Google PageSpeed Insights — mobile performance audit of aa-deepseek.com.cn · checked Jul 24, 2026
Dati e relazioni esterne
PD-20260724-285CC7 Recipient: xx1315aas@163.com Questo sito ti ha influenzato in qualche modo?
Se hai inserito credenziali dell'account, informazioni personali o di pagamento oppure hai scaricato un file da questo dominio, agisci immediatamente. Di seguito sono riportate le risorse per aiutarti a segnalare l'incidente e proteggerti.
Segnalalo alle autorità locali
Seleziona il tuo Paese per ottenere contatti ufficiali del crimine informatico o creare una bozza di reclamo →.
Verifica qualsiasi dominio
Analisi delle minacce utilizzando blocklist archiviate, WHOIS, DNS e prove di scansione pubblica
Scansiona oraSegnala un tentativo di phishing
Segnala i domini sospetti al nostro database delle minacce — proteggi la comunità
SegnalaFeed in tempo reale sulle minacce
Segnalazioni recenti di phishing e modifiche osservate della disponibilità
MonitoraRimani informato, rimani al sicuro
Controlla le minacce in tempo reale oppure contesta questa segnalazione se ritieni che si tratti di un falso positivo