Notification and current-status evidence
The sent-report ledger records the first outgoing report at .
The recorded recipient is abuse@dynadot.com.
The latest stored availability evidence still shows the domain reachable; 25 days has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
shop-dofus[.]fr
“Potion Valdermax - Actualites - Unity - le Unity stratégique.”
shop-dofus.fr — Непроверенный. Олицетворение бренда: Dofus; Тип мошенничества: Impersonation. Сводка доказательств: VirusTotal 16/91 (ADMINUSLabs, alphaMountain.ai, BitDefender, Chong Lua Dao, CyRadar); URLScan malicious verdict; PhishDestroy score 98/100. Регистратор: Dynadot.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
shop-dofus.fr is currently listed as an active generic phishing site with an elevated risk rating. The domain has been blocked by the PhishDestroy sinkhole, indicating that traffic to the domain is being redirected or denied by that mitigation service. In the AlienVault Open Threat Exchange the domain appears in fifty distinct threat‑intelligence pulses, reflecting repeated observations across multiple contributors. It is also present on a single external security blocklist, further confirming that at least one independent feed has classified it as malicious.
VirusTotal analysis shows that seventeen out of ninety‑one scanned security vendors returned a malicious verdict for the domain, providing concrete vendor consensus that the site hosts phishing content. The exact payload or lure employed by the site has not been publicly disclosed; page title and content analysis have not been released, so the specific brand or service being spoofed remains unknown. No additional infrastructure details such as registrar, hosting IP, ASN, or SSL certificate information are available in the current intelligence set. Consequently, defenders should treat any communication that references shop‑dofus.fr as potentially malicious, enforce URL filtering based on the domain, and incorporate it into existing phishing detection rules.
Continuous monitoring of threat‑intel feeds for updates on hosting details or observed payloads is advised, as further evidence may emerge that clarifies the phishing technique or target brand. Organizations employing email gateways or web proxies should block outbound connections to the domain and consider quarantine of any messages containing links to it. Incident response teams should also reference the existing PhishDestroy block and the AlienVault OTX pulses when correlating internal alerts, ensuring that detection mechanisms are aligned with the observed 17‑vendor malicious rating.
Данные сетевой безопасности
Процесс реагирования на угрозы
Статус в публичных блок-листах
Перекрёстная проверка данных об угрозах · source references
Анализ VirusTotal
Доказательства и внешние отчеты
PD-1784898044-shop-dofus.fr Recipient: abuse@dynadot.com Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание