Notification and current-status evidence
The sent-report ledger records the first outgoing report at .
The recorded recipient is icann@gname.com.
The latest stored availability evidence still shows the domain reachable; 7 months has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
teoeagramm.one
“Telegram”
teoeagramm.one — Доступен · доступ ограничен (HTTP 403). Олицетворение бренда: Telegram; Тип мошенничества: Social Media Phishing. Сводка доказательств: VirusTotal 13/91 (ADMINUSLabs, alphaMountain.ai, BitDefender, CyRadar, ESET); URLScan malicious verdict; CF Radar malicious; PhishDestroy score 89/100. Регистратор: Gname.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
Сводка доказательств
This domain functions as a brand impersonation infrastructure targeting Telegram. The page title "Telegram" and visual alignment suggest a deceptive login or session capture interface designed to harvest user credentials and potentially intercept authentication flows or messaging account access. The infrastructure indicates an active phishing campaign leveraging trust in a well-known messaging brand, likely aimed at credential theft and account takeover.
Technical indicators confirm malicious intent: domain created February 21, 2026, indicating very recent registration consistent with disposable phishing infrastructure. It is registered through Gname.com Pte. Ltd. and resolves to IP 172.67.145.31, hosted on Cloudflare (AS13335), a common reverse-proxy layer used to obscure origin servers. SSL certificate is issued by Google Trust Services / WE1, demonstrating use of automated TLS provisioning. Security telemetry shows 21/95 VirusTotal detections and presence on 1 security blocklist, with explicit blocking by PhishDestroy. These combined signals indicate active detection by multiple threat intelligence sources and ongoing malicious classification.
Users who have accessed this domain should assume potential credential compromise. Immediate actions include changing Telegram credentials, revoking active sessions across all devices, and enabling multi-factor authentication where available. Any reused passwords across services should be considered exposed and rotated immediately. Systems used to access the site should be scanned for malware or persistence mechanisms, particularly browser-based credential stealers or session hijackers. Additionally, monitor account activity for unauthorized logins and report suspicious sessions to relevant service security channels. Continued access attempts should be avoided, and the domain should be blocked at DNS or endpoint level to prevent re-exposure.
Данные сетевой безопасности
Финансовая инфраструктура
Адреса извлечены с фишинговой страницы.
Telegram
Хронология обнаружения
-
Статус домена
Недоступен → Доступен
-
Cloudflare Radar
Сканирование Cloudflare Radar сохранено · Открыть сканирование
-
Статус домена
Доступен → Недоступен
-
Cloudflare Radar
Сканирование Cloudflare Radar сохранено · Открыть сканирование
Процесс реагирования на угрозы
Статус в публичных блок-листах
Снимок отправленных доказательств
- Отправлено
- Записи журнала
- 1
- ID дела
PD-20260206-E7BFB7
Проверка по блок-листам
11 внешних источников под наблюдением · снимок от 09.09.2026
11 внешних источников под наблюдением Совпадений нет
Сохранённый снимок
Аналитика доменов
Технические деталиDNS, SAN в протоколе SSL, временные метки
ICANN OVERSIGHT
Аккредитация и контекст RAA
Аккредитация и контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Технологии · 1 identified
Web infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comАнализ VirusTotal
Архивные доказательства
Анализ производительности сайта
Google PageSpeed Insights — mobile performance audit of teoeagramm.one · checked Mar 1, 2026
Технологии
Выявлена 1 технология с высокой уверенностью
Доказательства и внешние отчеты
PD-20260206-E7BFB7 Recipient: icann@gname.com Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание