newslogistics[.]in
“SharePoint Online”
newslogistics.in — Não verificado. Representação da marca: Sharepoint; Tipo de golpe: Credential Phishing. Resumo das evidências: VirusTotal 13/91 (Abusix, alphaMountain.ai, BitDefender, Cluster25, CRDF); URLScan malicious verdict; Google Safe Browsing flagged; PhishDestroy score 89/100. Registrador: GoDaddy.
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
This domain, newslogistics.in, is flagged as a high-risk credential harvesting phishing site actively targeting users through social engineering tactics. Analysis indicates the infrastructure is designed to mimic legitimate login portals, tricking victims into submitting sensitive authentication details such as usernames, passwords, and multi-factor authentication codes. The threat type is classified as generic_phishing with a focus on credential theft, posing significant risks to both individual and organizational security. Infrastructure analysis reveals the domain resolves to the IP address 103.21.59.28 and was registered through GoDaddy on May 26, 2010. Detection metrics from VirusTotal indicate 9 out of 95 security vendors have flagged the domain as malicious, reflecting moderate but consistent detection across multiple engines. The SSL certificate is issued by Let’s Encrypt, a common tactic among phishing operators to lend a false sense of legitimacy. Google Safe Browsing has explicitly categorized the domain under SOCIAL_ENGINEERING, confirming its use in deceptive campaigns. Despite its long registration history, the domain remains active and continues to evade broader detection, suggesting ongoing operational refinement. Mitigation against this threat requires a multi-layered approach. Network-level protections should include blocking the domain and its associated IP address (103.21.59.28) at firewalls and DNS resolvers. Endpoint security solutions should be configured to detect and prevent access to known phishing domains, particularly those flagged for social engineering. User awareness training is critical, emphasizing the identification of phishing indicators such as mismatched URLs, unexpected login prompts, and suspicious SSL certificate issuers. Organizations should also enforce strict credential management policies, including the use of password managers and hardware-based multi-factor authentication to reduce the impact of credential theft. Continuous monitoring of threat intelligence feeds for updates on this domain and related infrastructure is recommended to adapt defenses as the campaign evolves.
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Tecnologias · 1 identified
Nginx is a web server that can also be used as a reverse proxy, load balancer, mail proxy and HTTP cache.
nginx.org 100% de confiançaAnálise do VirusTotal
Evidências e relatórios externos
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo