Notification and current-status evidence
The sent-report ledger records the first outgoing report at . A report was sent to the recorded registrar; contact details remain in Domain Intelligence. The latest stored availability evidence still shows the domain reachable; 5 months has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
callapp[.]us
“callapp.us”
Сохранённое наблюдение
Зафиксированное различие заголовков
Сводка доказательств
This domain is identified as a credential theft phishing site designed to harvest user authentication details through fraudulent login portals. Analysis indicates the infrastructure is specifically engineered to mimic legitimate service interfaces, tricking victims into submitting sensitive credentials such as usernames, passwords, and potentially multi-factor authentication codes. The absence of SSL encryption further increases exposure risk, as all data transmitted to callapp.us would be sent in plaintext, vulnerable to interception during transit. Infrastructure analysis reveals multiple technical indicators confirming malicious intent. The domain was registered on January 14, 2026, through NameCheap, Inc., and resolves to IP address 139.59.122.128, hosted on DigitalOcean, LLC infrastructure in Singapore. VirusTotal detection shows 12 out of 95 security vendors flagging the domain as malicious, while it appears on three independent security blocklists. The site was actively blocked by multiple reputation-based security systems prior to being taken offline, indicating widespread recognition of its fraudulent nature. Users who accessed callapp.us should immediately revoke any credentials entered on the site, even if no submission was completed. Monitor all accounts associated with the affected email or username for unauthorized access attempts. Enable multi-factor authentication on all critical accounts using app-based or hardware tokens, avoiding SMS-based verification where possible. Review recent login activity across all platforms for unfamiliar locations or devices. If financial or identity data was exposed, consider placing a fraud alert with relevant credit monitoring agencies. Network administrators should add the domain and its associated IP to internal blocklists to prevent future access attempts.
Снимок отправленных доказательств
- Отправлено
- Записи журнала
- 1
- ID дела
PD-20260228-6833EC- Заголовок сохранённой страницы
- Apache2 Ubuntu Default Page: It works
- PDF-файл
- PDF с доказательствами
Правовое основание
Полный текст доказательств
Policy Violations: Domain Registration Agreement prohibits hacking, misuse of domain to conduct attacks, scam and fraudulent activities; AUP allows immediate suspension
Applicable Laws: CFAA 18 U.S.C. §1030, Wire Fraud 18 U.S.C. §1343, CAN-SPAM Act
Data Coverage
Данные сетевой безопасности
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DNS4EU | callapp.us |
malicious | Sinkholed |
| Cloudflare DNS | callapp.us |
malicious | Sinkholed |
Процесс реагирования на угрозы
Проверка по блок-листам
10 внешних источников под наблюдением · снимок от 11.08.2026
8 внешних источников под наблюдением Совпадений нет
Хронология обнаружения
-
Cloudflare Radar
Сканирование Cloudflare Radar сохранено · Открыть сканирование
-
Cloudflare Radar
Сканирование Cloudflare Radar сохранено · Открыть сканирование
Анализ VirusTotal
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание