giftcardmall[.]org
“dhsgs035's Digital Business Card powered by Slink”
giftcardmall.org — Não verificado. Representação da marca: Godaddy; Tipo de golpe: Brand Impersonation. Resumo das evidências: VirusTotal 12/91 (ADMINUSLabs, alphaMountain.ai, BitDefender, Chong Lua Dao, CRDF); URLQuery 3 alerts; Spamhaus DBL_SPAM; PhishDestroy score 86/100.
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
This domain, giftcardmall.org, is flagged as a brand impersonation phishing site targeting GoDaddy, with elevated risk indicators confirmed by multiple security sources. Registered on February 21, 2026, the domain was hosted on Cloudflare infrastructure (IP 104.21.19.185, AS13335) and used nameservers ns7.alidns.com and ns8.alidns.com. Analysis of the SSL certificate reveals a WE1 classification, which is often associated with low-cost or automated certificate issuance, though not inherently malicious. The page title, 'dhsgs035's Digital Business Card powered by Slink,' does not align with typical GoDaddy branding or service pages, suggesting either misdirection or a generic front for malicious activity.
At the time of assessment, the domain was offline and blocked by PhishDestroy, with a presence on one security blocklist. VirusTotal detections from 11 of 93 security vendors further corroborate its malicious classification, though the specific payload or phishing kit remains unconfirmed. Defenders should treat this domain as compromised and prioritize blocking it at the DNS and network levels.
Given its association with Cloudflare and Alibaba nameservers, monitoring for re-emergence under similar infrastructure or certificate patterns is recommended. The domain's brief active period and rapid takedown suggest a disposable phishing operation, but historical WHOIS or passive DNS data may reveal additional linked infrastructure. No evidence of widespread abuse beyond the single blocklist entry was observed, but the GoDaddy impersonation angle warrants heightened scrutiny for credential harvesting or fraudulent service offerings.
Inteligência de segurança de rede
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Análise do VirusTotal
Evidências e relatórios externos
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo