Notification and current-status evidence
The sent-report ledger records the first outgoing report at .
The recorded recipient is abuse@github.com.
The latest stored availability evidence still shows the domain reachable; 4 months has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
memomu[.]xyz
“MEMOMU Game”
memomu.xyz — 확인되지 않음. 사기 유형: Gaming Scam. 증거 요약: VirusTotal 6/91 (alphaMountain.ai, Chong Lua Dao, CRDF, Forcepoint ThreatSeeker, Gridinsoft); PhishDestroy score 88/100. 등록기관: Namecheap.
원본 포렌식 기록을 보존하기 위해 아래의 상세 PhishDestroy AI 분석은 영어로 유지됩니다.
This domain, memomu.xyz, is flagged as a high-risk phishing infrastructure targeting users through a purported gaming platform. Registered on August 1, 2025, via NAMECHEAP INC, the domain remains active as of July 12, 2026, and resolves to IP address 185.199.108.153. The page title, 'MEMOMU Game,' suggests an attempt to lure victims with a gaming-related pretext, though the exact content and mechanics of the phishing operation are not yet analysed. The domain is associated with an SSL certificate issued by Let's Encrypt, a common feature in both legitimate and malicious sites, and is detected on two security blocklists, including PhishDestroy and BLP-Malware. Infrastructure analysis reveals the use of Firebase, Varnish, GitHub Pages, Unpkg, and Fastly, which may indicate an attempt to leverage legitimate cloud and CDN services to evade detection or improve scalability. The domain appears in 22 threat intelligence pulses on AlienVault OTX, signaling widespread recognition within the security community as malicious. While six of 95 security vendors on VirusTotal flag the domain, this detection rate does not confirm the absence of risk, particularly given the domain's presence on multiple blocklists and its recent registration. Defenders should prioritise blocking this domain at the network level, particularly in environments where gaming-related content is accessed. The use of GitHub Pages and Fastly suggests potential ties to distributed or rapidly changing infrastructure, which may require monitoring for related subdomains or IP shifts. Given the domain's age and continued activity, it is likely part of an ongoing campaign rather than a short-lived operation. Further analysis of the site's content, if accessible, could clarify the specific phishing techniques employed, such as credential harvesting or malware distribution.
위협 대응 Pipeline
공개 차단 목록 상태
저장된 캡처
도메인 인텔리전스
기술적 세부 사항DNS, SSL SAN, 타임스탬프
ICANN OVERSIGHT
인증 및 RAA 상황
인증 및 RAA 상황
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
사용 기술 · 5 identified
Firebase is a Google-backed application development software that enables developers to develop iOS, Android and Web apps.
firebase.google.com 신뢰도 100%Fastly is a cloud computing services provider. Fastly's cloud platform provides a content delivery network, Internet security services, load balancing, and video & streaming services.
www.fastly.com 신뢰도 100%VirusTotal 분석
증거 및 외부 보고서
PD-20260331-EAB9FC Recipient: abuse@github.com 이 사이트로 인해 영향을 받으셨나요?
계정 자격 증명, 개인 정보 또는 결제 정보를 입력했거나 이 도메인에서 파일을 다운로드한 경우 즉시 조치를 취하세요. 다음은 사건을 신고하고 자신을 보호하는 데 도움이 되는 리소스입니다.
지역 당국에 신고하십시오
공식 사이버 범죄 연락처 또는 불만사항 초안 작성 →를 받으려면 국가를 선택하세요.