Notification and current-status evidence
The sent-report ledger records the first outgoing report at .
The recorded recipient is complaint@gname.com.
The latest stored availability evidence still shows the domain reachable; 2 months has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
www-fifa[.]co
“FIFA World Cup 2026™ Tickets | Host Cities, Dates, Teams, Tickets”
www-fifa.co — Não verificado. Representação da marca: Fifa; Tipo de golpe: Credential Phishing. Resumo das evidências: VirusTotal 21/91 (ADMINUSLabs, alphaMountain.ai, ArcSight Threat Intelligence, BitDefender, Chong Lua Dao); URLQuery 2 alerts; URLScan malicious verdict; Spamhaus DBL_PHISH; PhishDestroy score 95/100. Registrador: Gname.
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
This domain, www-fifa.co, poses a significant threat as a credential theft scam. It aims to deceive users by mimicking the official FIFA World Cup 2026 website to trick them into entering sensitive information such as login credentials, personal data, and payment details. The threat is designed to capture this information and use it for malicious purposes, including identity theft and financial fraud.
Analysis indicates that www-fifa.co has been flagged by 18 out of 95 security vendors on VirusTotal, suggesting a high level of suspicion among the cybersecurity community. The domain was registered through Gname.com Pte. Ltd. on March 25, 2026, and has been associated with credential theft. The site has been taken offline, but its infrastructure, including the use of Let's Encrypt for an SSL certificate, React and jQuery for web technologies, and Cloudflare for additional security features, suggests a sophisticated setup aimed at gaining user trust. The domain also appears on 2 security blocklists and has been featured in 4 threat intelligence pulses on AlienVault OTX, further confirming its malicious intent.
If a user has visited www-fifa.co, they should immediately change their passwords and any other credentials that may have been entered on the site. It is recommended to monitor credit reports and bank statements for any unauthorized transactions. Users should also consider enabling two-factor authentication on all relevant accounts to add an additional layer of security. Reporting the incident to their bank and cyber security authorities can help mitigate potential damage and prevent others from falling victim to the same scam.
Inteligência de segurança de rede
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Tecnologias · 7 identified
React is an open-source JavaScript library for building user interfaces or UI components.
reactjs.org 100% de confiançajQuery is a JavaScript library which is a free, open-source software designed to simplify HTML DOM tree traversal and manipulation, as well as event handling, CSS animation, and Ajax.
jquery.com 100% de confiançaHTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org 100% de confiançaFacebook pixel is an analytics tool that allows you to measure the effectiveness of your advertising.
facebook.com 100% de confiançaCloudflare Browser Insights is a tool that measures the performance of websites from the perspective of users.
www.cloudflare.com 100% de confiançaCloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com 100% de confiançaHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100% de confiançaAnálise do VirusTotal
Análise de desempenho do site
Google PageSpeed Insights — mobile performance audit of www-fifa.co · checked Jun 26, 2026
Evidências e relatórios externos
PD-20260601-DE1918 Recipient: complaint@gname.com Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo