echo-preview[.]daikirai[.]com
Проверка домена echo-preview.daikirai.com на фишинг и безопасность
“Echo”
echo-preview.daikirai.com — Последний известный активный (HTTP 200). Тип мошенничества: Generic Phishing. Сводка доказательств: VirusTotal 3/91 (CRDF, Gridinsoft, SOCRadar); 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 76/100. Регистратор: Cloudflare.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
This domain, echo-preview.daikirai.com, is flagged as an active high-risk phishing site targeting users of Echo-related services. Infrastructure analysis reveals the domain was registered on May 11, 2026, through Cloudflare, Inc., and currently resolves to the IP address 104.21.5.79, located in Canada. The domain is served by Cloudflare nameservers julio.ns.cloudflare.com and stella.ns.cloudflare.com, a common pattern observed in phishing campaigns leveraging Cloudflare’s infrastructure to obscure origin servers and evade detection. The domain appears on three security blocklists and is actively blocked by multiple threat intelligence feeds, including PhishDestroy, MetaMask, and SEAL. Despite these detections, the domain has not yet been flagged by VirusTotal, with 0 out of 95 engines reporting malicious activity as of July 12, 2026. The page title, 'Echo,' suggests an attempt to mimic legitimate Echo services, though the exact content and targeting method remain unconfirmed due to the absence of deeper forensic analysis. The domain’s SSL certificate is issued by Google Trust Services, providing a superficial layer of legitimacy while failing to mitigate the underlying threat. Defenders should treat this domain as actively malicious based on its presence on multiple blocklists and its association with known phishing infrastructure. The HTTP status code 200 indicates the site is operational, and the lack of detections in VirusTotal should not be interpreted as a sign of safety, given the domain’s inclusion in other reputable threat feeds. Network-level blocking is recommended for all endpoints, and security teams should monitor for connections to 104.21.5.79 or related subdomains under daikirai.com. Further investigation into the domain’s hosting environment and potential ties to broader phishing campaigns is advised, particularly given its recent registration and use of Cloudflare’s proxy services.
Процесс реагирования на угрозы
Статус в публичных блок-листах
Аналитика доменов
Технические сведенияDNS, SAN в протоколе SSL, временные метки
ICANN OVERSIGHT
Registration: daikirai.com
Аккредитация и контекст RAA
Аккредитация и контекст RAA
Registrar accreditation and DNS abuse obligations
For the registrable domain daikirai.com behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Анализ VirusTotal
Доказательства и внешние отчеты
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание