Перейти к отчёту о безопасности
Checked 09.08.2026 Ref 0DEEEED1

MALICIOUS — CRITICAL

Проверка домена fashcup.com на фишинг и безопасность

fashcup[.]com

PhishDestroy identifies fashcup.com as an active phishing site posing as a fashion retail portal to harvest payment credentials and personal data.

71/100 evidence score · Critical
VirusTotal
2/91
Blocklists
No stored match
Доступность
Последний известный активный · HTTP 200
Report / Add Evidence Appeal this listing
2026-03-27 17:02 UTCПоследний известный активный · HTTP 200

Do not enter credentials, seed phrases, payment details, or personal information on this domain.

⚠️
Этот домен был отмечен как вредоносный
Механизмы безопасности сообщают об обнаружении: 2. Будьте предельно осторожны — не вводите учетные данные или личную информацию.
ABUSE NOTICE · 7D+ OPEN Outgoing abuse reports are recorded; the latest stored availability evidence still shows the domain reachable.
Notification and current-status evidence

The sent-report ledger records the first outgoing report at . The recorded recipient is abuse@nicenic.net, abuse@verisign-grs.com, compliance@icann.org. The latest stored availability evidence still shows the domain reachable; 4 months has elapsed since the first outgoing report.

ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.

Elapsed since first report
4 months
Reports sent
1
Latest case ID
PD-20260327-00047A
Current status
HTTP 200 at latest stored check
Jump to section
Краткий обзор отчёта

fashcup.com — Последний известный активный (HTTP 200). Тип мошенничества: Gaming Scam. Сводка доказательств: VirusTotal 2/91 (Gridinsoft, SOCRadar); PhishDestroy score 71/100. Регистратор: NiceNIC.

Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.

Evidence Analysis

Ref 0DEEEED1

PhishDestroy identifies fashcup.com as an active phishing site posing as a fashion retail portal to harvest payment credentials and personal data. The domain exhibits classic phishing red flags—rapid registration (April 04, 2025), freshly issued SSL via Google Trust Services, and hosting on a bulletproof IP address (104.21.51.28). The threat actors appear to be leveraging a generic drainer kit repurposed for credential theft under the guise of high-end fashion promotions.

Technical indicators confirm the site’s hostile intent: VirusTotal currently flags 0/95 security engines, indicating zero detection as of the latest scan, while the domain was registered through NICENIC INTERNATIONAL GROUP CO., LIMITED. The SSL certificate issued by Google Trust Services is valid but does not mitigate the risk, as it is commonly abused for short-lived phishing campaigns. The IP address 104.21.51.28 resolves through Cloudflare, a tactic often used to evade takedowns and delay takedown response.

This domain is currently active and under active monitoring by PhishDestroy. The site has not yet been widely blacklisted, maintaining a low detection footprint despite its malicious nature. Users are strongly advised to avoid interacting with fashcup.com and report any encountered instances immediately. The remaining risk is high due to the domain’s youth, evasive infrastructure, and lack of current blocklist presence. Immediate blocking at the network level is recommended for organizations.

Stored source results

Recorded verdicts and infrastructure observations for this domain.

VirusTotal
VirusTotal
2 det.
Сертификат TLS
Google Trust Services
Возраст
5 mo
Зафиксированный статус
Последний известный активный 200
PhishDestroy
DestroyList
В списке
Reports Sent
1
Охват данных12 recorded checks
VirusTotal 2 / 91 URLQuery checked — no detections recorded PhishStats checked — no match recorded OTX no community references CF Radar scan completed URLScan capture сохраненный отчет URLScan verdict Анализ завершён DNS-блокировки 11 проверено — блокировок нет TLS valid certificate, 86d WHOIS 5 mo old Снимок экрана 3 captures · 3 sources Цепочка перенаправлений не исследовано
Данные сетевой безопасности Registrar context
Registrar context NiceNIC
Stored registration data identifies NICENIC INTERNATIONAL GROUP CO., LIMITED (IANA 3765) as the registrar. PhishDestroy maintains separate NiceNIC abuse-report research; registrar association is contextual and is not an independent detection for this domain.
NiceNIC Verdict Full Investigation

Процесс реагирования на угрозы

Открытие
Checks
Reports
Доступность
11/12
Угроза устранена
fashcup.com обнаружены и помещены в очередь для полного анализа
27.03.2026
URLScan.io Capture
Stored URLScan report with capture artifacts
URLScan Verdict
Анализ URLScan завершен; этот результат веб-захвата не меняет вердикт об угрозе странице · score 0
29.07.2026
Cloudflare Radar Report
A stored Cloudflare Radar report is available. The report link alone is not a malicious verdict and does not prove that every network field was captured.
VirusTotal
2/91 recorded on VirusTotal
26.07.2026
Google Safe Browsing
27.03.2026
Registrar Context: NiceNIC
Separate registrar research is available. Registrar association is contextual and is not scored as an independent detection.
Forensic Evidence Collected
Stored evidence from URLScan.io, URLQuery, stored screenshot
Technical Analysis Recorded
Отчет содержит сохраненные технологии или результаты судебно-медицинской экспертизы.
09.08.2026
Sent Report Recorded
Stored sent-report record for registrar NICENIC INTERNATIONAL GROUP CO., LIMITED, hosting provider, 1 abuse contact
abuse@nicenic.net
27.03.2026
Опубликовано «DestroyList»
27.03.2026
Monitoring Continues
Домен остается доступным или доступ к нему ограничен; будущие проверки могут обновить это наблюдение.

Статус в публичных блок-листах

Сохранённый снимок

Заголовок страницы
CS2 | FASTCUP
Сертификат TLS
Valid transport encryption · Выдан Google Trust Services · valid for 86 days

Аналитика доменов

Домен
URLScan Verdict Анализ завершён score 0 report ↗
Сервер / ASN cloudflare · AS13335 Cloudflare, Inc.
IP Context Cloudflare shared edge origin IP hidden Репутация Edge-IP не связана с этим доменом.
Регистратор NiceNIC RU(RU) PhishDestroy Investigation
Контакт для жалобabuse@nicenic.net
IP-адрес 104.21.51.28 CDN
ГеолокацияCA Toronto, CA
СетьAS13335 · Cloudflare, Inc.
Обратный поиск IPviewdns.info → rapiddns.io →
Исходный IP-адрес скрыт за прокси-сервером CDN. Результаты обратного IP-адреса для граничного адреса содержат несвязанных клиентов; для определения источника требуется пассивный DNS или данные прозрачности сертификатов.
РегистрацияСоздано 27.03.2026 (135d)
Elapsed Since First Report 26h
Что мы учитываем Raw elapsed time since the first stored abuse report. It is not a registrar response-time measurement. Latest observed status: Последний известный активный.
Что содержит каждый отчет Сохраненные записи исходящих отчетов могут ссылаться на доказательства, доступные на данный момент, такие как вердикты поставщиков, регистрационные данные, сведения о хостинге, классификации или снимки экрана. На этой странице не указывается точная доставленная полезная нагрузка, получение, подтверждение или действие получателя.
Статус HTTP200
Технические сведенияDNS, SAN в протоколе SSL, временные метки
Впервые обнаружено27.03.2026
IoC Extractionscanned 29.07.20260 wallet · 0 Telegram IoCs
Submitted URLhttps://fashcup.com/
Серверы имёнjasper.ns.cloudflare.comkara.ns.cloudflare.com
TLS Fingerprint
TLS Observationvalid from 24.03.2026scanned 28.03.2026
Case ID
ICANN OVERSIGHT

Аккредитация и контекст RAA

Registrar accreditation and DNS abuse obligations

For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.

Accreditation is a contract, not a safety certification.

RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.

Accountability draft Ничего не отправляется автоматически.

Latest Classified Outcome 2026-08-09 02:43:44 UTC

Primary outcome Live content reason: Ordinary HTTP content served 90% confidence
Attribution source: Current Http Probe
Evidence layers Availability: Content serving Content: Content served at root DNS: Resolved Registration: Active
Latest HTTP observation Live content Ordinary HTTP content served 90% 2026-08-09 02:43:44 UTC
RDAP registration Активен NameSilo, LLC · IANA 1479 RDAP HTTP 200 source: Rdap Status Collector clientTransferProhibited expires 2028-06-24 13:19:24 UTC checked 2026-08-05 18:58:30 UTC
Observed timeline last reachable: 2026-08-09 02:43:44 UTC last content: 2026-08-09 02:43:44 UTC
Availability, content, DNS and registration are independent evidence layers. NXDOMAIN, an unreachable origin or missing content alone does not prove registrar action. A registrar or provider is credited only when a direct technical marker identifies that actor. Report causality is shown separately.
Технологии · 3 identified
Cloudflare Browser Insights
Analytics RUM

Performance monitoring tool that measures website speed from real users.

www.cloudflare.com
Cloudflare
CDN

Web infrastructure and security company providing CDN, DDoS mitigation, and DNS services.

www.cloudflare.com
HTTP/3
Miscellaneous

Third major version of HTTP protocol, built on QUIC for faster, more reliable connections.

Detected via Cloudflare Radar · Wappalyzer engine
Пожаловаться на этот домен Предоставьте доказательства и помогите защитить других

Анализ VirusTotal

2 / Поставщики средств безопасности 91 отметили этот домен
View on VT
Last analyzed First positive detection Previous stored snapshot: 0 detections
Gridinsoft
SOCRadar
Анализ производительности сайта

Google PageSpeed Insights — mobile performance audit of fashcup.com · checked Mar 27, 2026

78
Needs Work
Performance
FCP
2.75s
First Contentful Paint
LCP
4.38s
Largest Contentful Paint
CLS
0
Cumulative Layout Shift
TBT
5ms
Total Blocking Time
SI
4.52s
Speed Index
Powered by Google PageSpeed Insights · Mobile strategy · Scores: 90-100 Good 50-89 Needs Work 0-49 Poor
Доказательства и внешние отчетыIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
If credentials were compromised, report immediately. Do not engage with recovery scammers.

Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.

Европол
Найдите официальный канал отчетности для вашей страны ЕС
National police directory
Остерегайтесь мошенников, предлагающих услуги по восстановлению данных! Преступники могут снова связаться с жертвами, притворяясь следователями, адвокатами или агентами по восстановлению. Не платите авансовые платежи и не делитесь учетными данными. Узнайте больше о мошенничестве при получении компенсаций →

Сообщите об этом в местные органы власти

Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.

Каталог 97 стран
Черновик по шаблону • помощь AI с формулировками включается только с отдельного согласия. Просмотрите и отправьте его самостоятельно
Вставить этот отчетRead-only HTML widget
HTML · IFRAME

Вставить этот отчет

Разместите эту информацию об угрозах на своём сайте или в блоге

embed.html
<iframe
  src="https://phishdestroy.io/ru/embed/domain/fashcup.com"
  title="PhishDestroy threat report for fashcup.com"
  width="100%" height="320"
  loading="lazy"
  referrerpolicy="no-referrer"
  sandbox="allow-same-origin allow-popups allow-popups-to-escape-sandbox"
  style="border:0;border-radius:12px;max-width:100%"
></iframe>

Очень искреннее благодарственное письмо

Генератор сатирических черновиков

Получатель
Контекст сборов

Это сатирический черновик. Суммы сборов являются оценочными; мы не утверждаем, что они точно относятся к этому домену.