Notification and current-status evidence
The sent-report ledger records the first outgoing report at .
The recorded recipient is abuse@ifastnet.com.
The latest stored availability evidence still shows the domain reachable; 4 months has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
bellkinpower[.]xo[.]je
“Masuk - Belkin Power Bank”
bellkinpower.xo.je — 未検証. 詐欺タイプ: Generic Phishing. 証拠の概要: VirusTotal 4/91 (CRDF, CyRadar, Gridinsoft, URLQuery); URLQuery 3 alerts; Spamhaus DBL_PHISH; PhishDestroy score 70/100. レジストラ: Ifastnet.
元のフォレンジック記録を保持するため、下の PhishDestroy AI 詳細分析は英語のままです。
The domain bellkinpower.xo.je hosts a fraudulent login page titled "Masuk - Belkin Power Bank," likely designed to impersonate the Belkin brand. The page poses a credential theft threat by tricking users into entering sensitive account information under the guise of a legitimate power bank product portal.
Technical analysis reveals the site is flagged by 4 out of 95 VirusTotal vendors, including LevelBlue, Seclookup, SOCRadar, and URLQuery. It is listed on 1 blocklist. The domain IP address is 185.27.134.138, located in Great Britain and hosted by I FastNet LTD. The domain was registered through Ifastnet registrar on 2026-03-23. The SSL certificate is issued by ZeroSSL / ZeroSSL ECC Domain Secure Site CA.
The site is currently down or offline. GridinSoft trust rating is 0 out of 100, and the DOM risk score is 56, indicating a moderate to high risk level despite the site being inactive.
ネットワークセキュリティインテリジェンス
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DigiCert UltraDNS | bellkinpower.xo.je |
malicious | Sinkholed |
| Quad9 DNS | bellkinpower.xo.je |
malicious | Sinkholed |
| DigiCert UltraDNS | files.catbox.moe |
malicious | Sinkholed |
脅威対応 Pipeline
公開ブロックリスト登録状況
使用技術 · 3 identified
Google platform for building mobile and web applications with backend services.
High-performance HTTP server and reverse proxy, known for stability and low resource usage.
Web platform based on Nginx with LuaJIT for scalable web apps.
VirusTotalによる分析
証拠および外部報告書
PD-20260323-FD6346 Recipient: abuse@ifastnet.com このサイトによって何か影響を受けましたか?
アカウント資格情報、個人情報、支払い情報を入力した場合、またはこのドメインからファイルをダウンロードした場合は、すぐに対処してください。インシデントを報告し、自分自身を守るのに役立つリソースを以下に示します。
お住まいの地域の当局へ報告してください
サイバー犯罪の公式連絡先 または 苦情草稿を作成する → を取得するには、国を選択してください。
任意のドメインを確認する
保存されたブロックリスト、WHOIS、DNS、および公開スキャン証拠を使用した脅威分析
今すぐスキャンフィッシングを報告する
不審なドメインを当社の脅威データベースに報告してください — コミュニティを守りましょう
レポートリアルタイム脅威情報フィード
最近のフィッシングレポートと観察された可用性の変化
監視最新情報を入手し、安全を確保しましょう
リアルタイムの脅威を監視するか、誤検知だと思われる場合はこのリストに異議を申し立ててください