vpn4[.]my
“Mamma.com Search - Trust Mamma to provide the best search results”
vpn4.my — Conteúdo indisponível (HTTP 502). Representação da marca: Coinbase; Tipo de golpe: Seed Phrase Theft. Resumo das evidências: VirusTotal 1/93 (SOCRadar); PhishDestroy score 61/100.
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
As of July 25, 2026, the domain vpn4.my is flagged as a generic phishing domain with an elevated risk level. This domain was created on February 21, 2026, and has been taken offline. The current status of the domain is offline, which may indicate that the threat has been mitigated, but this does not guarantee the domain is safe, as it could be reactivated at any time. The domain resolves to the IP address 186.2.166.73, which is located in the United Arab Emirates and is associated with the ASN AS59692 IQWeb FZ-LLC. Infrastructure analysis reveals that the domain was hosted using PHP and the Apache HTTP Server, with additional technologies including jQuery UI, jQuery CDN, jQuery, Google Tag Manager, and Contentsquare.
The page title for the domain was 'Mamma.com Search - Trust Mamma to provide the best search results,' which is unusual given the domain's name and the reported threat. This discrepancy may suggest that the domain was being used to masquerade as a legitimate search engine. The domain appears in one threat intelligence pulse on AlienVault OTX and is listed on one security blocklist, specifically PhishDestroy. While the domain is currently offline, security professionals should remain vigilant and monitor for any signs of reactivation.
Defenders should also ensure that their security policies and tools are updated to block this domain and educate users about the risks of phishing attacks. The domain's SSL certificate is classified as R12, which may indicate a higher level of sophistication in the phishing operation. Given the minimal detections and the domain's current offline status, further investigation is recommended to understand the full scope of the threat. However, the available evidence strongly suggests that the domain was used for phishing activities and should be treated with caution.
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Tecnologias · 7 identified
Server-side scripting language designed for web development.
Most widely used open-source HTTP server software.
Legacy JavaScript library — DOM manipulation and AJAX helpers. Still widely present on older sites.
Legacy JavaScript library — DOM manipulation and AJAX helpers. Still widely present on older sites.
Fast, small JavaScript library simplifying HTML manipulation, event handling, and Ajax.
Tag management system for deploying marketing and analytics tags.
tagmanager.google.comAnálise do VirusTotal
Evidências e relatórios externos
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo