jopobu[.]cc
“Website bozeqijo.cc is ready. The content is to be added”
jopobu.cc — Erro no servidor (HTTP 502). Representação da marca: Trust Wallet; Tipo de golpe: Credential Phishing. Resumo das evidências: VirusTotal 20/94 (ADMINUSLabs, alphaMountain.ai, BitDefender, Chong Lua Dao, Cluster25); URLQuery 2 alerts; PhishDestroy score 95/100. Registrador: NiceNIC.
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
This domain, jopobu.cc, is flagged as a generic phishing resource designed to harvest user credentials through deceptive landing pages. Analysis indicates no direct brand impersonation at the time of detection; however, the presence of a placeholder page titled 'Website bozeqijo.cc is ready. The content is to be added' suggests an infrastructure prepared for rapid deployment of phishing content. No drainer kit signatures or cryptocurrency wallet identifiers were observed in the initial scan, though the domain's configuration aligns with common pre-attack staging patterns used in credential theft campaigns. Infrastructure analysis reveals the following technical indicators: the domain resolves to IP address 144.31.219.5, hosted under autonomous system AS207957 (SERV.HOST GROUP LTD) in Germany. Registered through NICENIC INTERNATIONAL GROUP CO., LIMITED on November 28, 2025, the domain lacks an SSL certificate, increasing exposure to interception risks. Detection metrics show 20 out of 95 security engines on VirusTotal flagging the domain as malicious, while it appears on a single security blocklist. Google Safe Browsing currently does not list the domain, though this may reflect a lag in propagation rather than a clean status. The domain has been taken offline following detection, reducing immediate user exposure. However, the registrar and hosting provider remain active, allowing for potential reactivation or migration to alternative infrastructure. The absence of SSL encryption and the use of a recently registered domain with minimal blocklist coverage suggest an attempt to evade detection during early deployment phases. Users are advised to treat any prior interactions with the domain as compromised and to monitor accounts for unauthorized access. Organizations should update internal blocklists to include both the domain and its associated IP address to mitigate residual risk from potential re-emergence.
Inteligência de segurança de rede Registrar context
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Latest Classified Outcome 2026-08-14 03:09:31 UTC
Análise do VirusTotal
Evidências e relatórios externos
PD-20260318-AF163D Recipient: abuse@nicenic.net, abuse@verisign-grs.com, compliance@icann.org Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo