Notification and current-status evidence
The sent-report ledger records the first outgoing report at .
The recorded recipient is abuse@contabo.de.
The latest stored availability evidence still shows the domain reachable; 11 days has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
echo[.]product-sid[.]us
“Echo — Ask. Listen. Learn.”
echo.product-sid.us — 마지막으로 알려진 활성 (HTTP 308). 증거 요약: VirusTotal 6/91 (alphaMountain.ai, Forcepoint ThreatSeeker, Fortinet, Gridinsoft, Kaspersky); Spamhaus DBL_PHISH; 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 85/100.
원본 포렌식 기록을 보존하기 위해 아래의 상세 PhishDestroy AI 분석은 영어로 유지됩니다.
echo.product-sid.us is a subdomain of product-sid.us. PhishDestroy first observed the hostname on Aug 11, 2026. The captured page title is “Echo — Ask. Listen. Learn.”. Current evidence score: 85/100 (critical).
Positive findings are stored from 4 sources: VirusTotal, MetaMask, SEAL, and Spamhaus DBL. VirusTotal recorded 6 detections among 91 engines: alphaMountain.ai, Forcepoint ThreatSeeker, Fortinet, Gridinsoft, Kaspersky, SOCRadar on Aug 21, 2026 at 06:11 UTC. MetaMask and SEAL listed the hostname in the separate external-blocklist snapshot on Aug 22, 2026 at 10:20 UTC. Spamhaus DBL: DBL_PHISH on Aug 11, 2026 at 14:30 UTC. Non-positive and contextual checks: URLQuery recorded no positive detection on Aug 11, 2026 at 10:46 UTC. Google Safe Browsing returned no flag on Aug 21, 2026 at 06:12 UTC. URLScan completed without a malicious verdict (score 0) on Aug 11, 2026 at 11:08 UTC.
HTTP 308 was recorded on Aug 22, 2026 at 10:00 UTC. At collection time, the hostname resolved to 217.216.75.57 on AS141995 (CAPL-AS-AP - Contabo Asia Private Limited, SG). The recorded endpoint location is Singapore, SG. The stored server header is Caddy. DOM analysis on Aug 11, 2026 at 14:22 UTC returned 85/100. The evidence archive retains 4 visual captures from PhishDestroy, URLScan, URLQuery, and Cloudflare Radar. TLS metadata lists Let's Encrypt as the certificate issuer.
The content indicators and 4 positive source findings support the current phishing classification. The stored fields do not identify an impersonated brand or victim interaction.
위협 대응 Pipeline
공개 차단 목록 상태
사용 기술 · 3 identified
Node.js is an open-source, cross-platform, JavaScript runtime environment that executes JavaScript code outside a web browser.
nodejs.org 신뢰도 100%Express is a web application framework for Node.js, released as free and open-source software under the MIT License. It is designed for building web applications and APIs.
expressjs.com 신뢰도 100%HTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 신뢰도 100%VirusTotal 분석
보관된 증거
사이트 성능 분석
Google PageSpeed Insights — mobile performance audit of echo.product-sid.us · checked Aug 11, 2026
증거 및 외부 보고서
PD-20260811-D729EB Recipient: abuse@contabo.de 이 사이트로 인해 영향을 받으셨나요?
계정 자격 증명, 개인 정보 또는 결제 정보를 입력했거나 이 도메인에서 파일을 다운로드한 경우 즉시 조치를 취하세요. 다음은 사건을 신고하고 자신을 보호하는 데 도움이 되는 리소스입니다.
지역 당국에 신고하십시오
공식 사이버 범죄 연락처 또는 불만사항 초안 작성 →를 받으려면 국가를 선택하세요.