ftjzh[.]com
“COINVOYAGES”
Resumo das evidências
PhishDestroy identifies ftjzh.com as a confirmed active phishing domain deployed for fraudulent tech support schemes. This domain mimics legitimate service portals to deceive users into disclosing payment credentials or granting remote access to threat actors. The server’s recent creation and undetected status on VirusTotal indicate an evolving campaign targeting less technical users through social engineering and impersonation tactics. Security teams should classify this domain as HIGH PRIORITY due to the potential for credential harvesting and financial loss. This domain was flagged by PhishDestroy with the following technical indicators: VirusTotal detection ratio is 2 out of 95 security engines as of the report date, indicating zero proactive blocking across industry tools; SSL certificate is issued by Google Trust Services, leveraging the CA’s reputation to avoid browser warnings; domain registration was handled through NameSilo, LLC, a registrar frequently abused by malicious actors for bulletproof hosting; the server resolves to IP 172.67.173.44, linked to Cloudflare infrastructure often exploited to obfuscate origin; domain creation occurred on June 26, 2025, reflecting an extremely recent campaign lifecycle. Despite the absence of public blocklists, the combination of fresh registration, low detection, and trust certificate issuance suggests preemptive avoidance rather than confirmed innocence. To mitigate exposure to this tech support scam, users should immediately block ftjzh.com at the DNS and firewall level using threat intelligence feeds. Enterprises are advised to update proxy rules, email security gateways, and browser allowlists to deny access to this domain. If interaction has already occurred, disconnect from the network, scan for unauthorized remote access tools, revoke any entered credentials, and file incident reports with local CERT teams. Monitor outbound DNS queries for related domains to detect lateral movement. Avoid visiting the site entirely, as the SSL certificate provides no safety guarantee—trust certificates only validate encryption, not legitimacy.
Instantâneo das evidências enviadas
- Enviado
- Registros do livro-razão
- 1
- ID do caso
PD-20260406-9B26C4- Título da página capturada
- COINVOYAGES
- Artefato PDF
- Evidência em PDF
Base jurídica
Texto completo da evidência
Illegal Activities: Active phishing operation targeting victims
Fraud & Deception: Impersonation of legitimate services
Identity Theft: Collection of credentials under false pretenses
Applicable Laws (US):
18 U.S.C. § 1343 - Wire Fraud
18 U.S.C. § 1030 - Computer Fraud and Abuse Act (CFAA)
15 U.S.C. § 45 - FTC Act (Deceptive Practices)
Federal laws prohibit wire fraud, computer fraud, and deceptive business practices.
Action Required: This evidence-backed report demonstrates clear violations requiring suspension per your policies. Continued hosting exposes your organization to regulatory scrutiny and potential legal liability.
Data Coverage
Inteligência de segurança de rede
Pipeline de resposta a ameaças
Cobertura de listas de bloqueio
10 fontes externas monitoradas · instantâneo de 11/08/2026
Captura armazenada
Inteligência de Domínios
Detalhes técnicosDNS, nomes TLS e datas
ICANN OVERSIGHT
Credenciamento e contexto RAA
Credenciamento e contexto RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Análise do VirusTotal
Análise de desempenho do site
Google PageSpeed Insights — mobile performance audit of ftjzh.com · checked Apr 6, 2026
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo