Notification and current-status evidence
The sent-report ledger records the first outgoing report at . A report was sent to the recorded registrar; contact details remain in Domain Intelligence. The latest stored availability evidence still shows the domain reachable; 4 months has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
mysaiban[.]com
“साईबन निसर्गाचा कुशीत वसलेले एक टुमदार घरटं...”
mysaiban.com was observed on 2026-07-12 as an active brand‑impersonation site targeting Google. The domain was registered on 2017-06-22 through PDR Ltd. d/b/a PublicDomainRegistry.com and resolves to 103.117.212.145, an address owned by AS140641 YOTTA NETWORK SERVICES PRIVATE LIMITED in India. The site returns HTTP 200 and presents a page titled “साईबन निसर्गाचा कुशीत वसलेले एक टुमदार घरटं…”, which does not reference the impersonated brand but is used as a lure in email‑based scams. The infrastructure is hosted behind a LiteSpeed web server and employs a free TLS certificate, indicating a valid TLS handshake but offering no authentication of the operator.
Static analysis shows the page loads YouTube embeds, Bootstrap, Slick, OWL Carousel, jQuery, Google Hosted Libraries and Google Analytics, suggesting a typical content‑driven template rather than a custom phishing kit. The domain received a Gridinsoft trust score of 0/100 and appears on one external blocklist. VirusTotal scanned the host and 11 of 95 security vendors flagged it as malicious, reinforcing the suspicion. Nameservers are ns301.ownmyserver.com, ns302.ownmyserver.com, ns311.ownmyserver.com and ns312.ownmyser, all pointing to the same hosting provider.
Analysis confirms the site is being used to impersonate Google in email campaigns, likely to harvest credentials or deliver malware. While the exact payload delivered to victims remains unknown, the presence of analytics and video elements suggests the operator tracks visitor interaction. Defenders should block the domain and its associated IP at perimeter firewalls, update email filtering rules to flag messages containing links to mysaiban.com, and consider sinkholing the host to disrupt traffic. Continuous monitoring of the listed nameservers and the ASN is recommended, as the operator may shift to adjacent IP ranges or replicate the site under new domains.
Record della segnalazione inviata
Istantanea delle prove inviate
- Inviato
- Voci del registro
- 1
- ID del caso
PD-20260318-2784A8- Titolo della pagina acquisita
- साईबन निसर्गाचा कुशीत वसलेले एक टुमदार घरटं...
- Artefatto PDF
- Prova in PDF
Testo completo delle prove
Acceptable Use Policy: The domain mysaiban.com is engaged in phishing activities, which constitutes a clear violation of your AUP prohibiting fraud and deception.
Terms of Service: The ongoing use of this domain for illegal activities breaches your TOS, which reserves the right to suspend or terminate services for such violations.
Applicable Laws (IN):
Information Technology Act, 2000 (Section 66): This section addresses computer-related offenses, including hacking and phishing, making such activities punishable under Indian law.
Indian Penal Code (Section 420): This section pertains to cheating and dishonestly inducing delivery of property, applicable to phishing schemes that deceive individuals into providing sensitive information.
Regulatory Note: Failure to take prompt action against this domain may result in liability under applicable laws and could expose your organization to regulatory scrutiny. Immediate suspension is advised to mitigate potential risks.
Informazioni sulla sicurezza di rete
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Private YARA rules | www.youtube.com/s/player/21cd2156/player_es6.vflset/en_us/base.js |
audit | Hunting_JS_WebAssembly |
| DNS4EU | mysaiban.com |
malicious | Sinkholed |
Pipeline di risposta alle minacce
Copertura delle blocklist
10 fonti · sincronizzato il 09/08/2026
Cronologia del rilevamento
Osservazioni memorizzate in ordine cronologico.
-
VirusTotal
VirusTotal: 0 → 9
Acquisizione salvata
Analisi dei domini
Dettagli tecniciDNS, SAN SSL, timestamp
ICANN OVERSIGHT
Accreditamento e contesto RAA
Accreditamento e contesto RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Analisi di VirusTotal
Analisi delle prestazioni del sito
Google PageSpeed Insights — mobile performance audit of mysaiban.com · checked Mar 18, 2026
Questo sito ti ha influenzato in qualche modo?
Se hai inserito credenziali dell'account, informazioni personali o di pagamento oppure hai scaricato un file da questo dominio, agisci immediatamente. Di seguito sono riportate le risorse per aiutarti a segnalare l'incidente e proteggerti.
Segnalalo alle autorità locali
Seleziona il tuo Paese per ottenere contatti ufficiali del crimine informatico o creare una bozza di reclamo →.
Verifica qualsiasi dominio
Analisi delle minacce utilizzando blocklist archiviate, WHOIS, DNS e prove di scansione pubblica
Scansiona oraSegnala un tentativo di phishing
Segnala i domini sospetti al nostro database delle minacce — proteggi la comunità
SegnalaFeed in tempo reale sulle minacce
Segnalazioni recenti di phishing e modifiche osservate della disponibilità
MonitoraRimani informato, rimani al sicuro
Controlla le minacce in tempo reale oppure contesta questa segnalazione se ritieni che si tratti di un falso positivo