VirusTotal
12 / 91
“NAGA99 LOGIN - Platform Digital Spin Demo Gratis Gampang Jepe”
Analysis indicates that www.zawadgroup.com is currently active and classified as a high‑risk brand‑impersonation campaign targeting Adobe credentials.
Özgün adli kaydı korumak için aşağıdaki ayrıntılı PhishDestroy AI analizi İngilizce bırakılmıştır.
Analysis indicates that www.zawadgroup.com is currently active and classified as a high‑risk brand‑impersonation campaign targeting Adobe credentials. The site returns HTTP 200 and presents a page titled “NAGA99 LOGIN - Platform Digital Spin Demo Gratis Gampang Jepe,” which matches the credential‑phishing description provided in the intelligence feed.
Infrastructure examination shows the domain was created on September 17 2024 and registered through Spaceship, Inc. Authoritative name servers ns1.usa.cloudns.io, ns2.usa.cloudns.io, ns25.webrserver.com, and ns26.webrserver.com resolve the domain to IP address 185.73.9.3. The address resides in the United States and is announced by ASN 52148, operated by Enix Ltd. TLS termination is provided by a Let’s Encrypt certificate (R13), and the web server identifies LiteSpeed technology with support for HTTP/3 and reCAPTCHA challenges.
Threat intelligence corroborates malicious intent: the domain appears on a single blocklist and has been explicitly blocked by PhishDestroy. AlienVault OTX references the domain in one threat‑intel pulse, and VirusTotal records twelve of ninety‑five security vendors flagging the host as malicious. Gridinsoft assigns a trust score of zero out of one hundred, reinforcing the assessment of a low‑reputation asset. The combination of Adobe impersonation, the credential‑phishing kit label, and the observed page title further substantiates the phishing hypothesis.
Defenders should treat www.zawadgroup.com as a confirmed malicious indicator. Immediate remediation includes adding the domain and its resolving IP (185.73.9.3) to deny‑list rules, monitoring DNS queries for the associated name servers, and inspecting outbound traffic for attempts to contact the host. Continuous feed updates from blocklist providers and threat‑intel platforms are advised to capture any subsequent infrastructure changes.
Bu ana bilgisayar için saklanmış tarayıcı-karşı-tarayıcı gözlemleri ile Keitaro tarzı trafik dağıtım sistemleri için gerçek zamanlı parmak izi kontrolü.
Tarayıcı notu: unavailable: raw=connection_error; http=0; via=http_proxy; error=SOCKSHTTPConnectionPool(host='duplicate-disabled-12421.invalid', port=80): Max retries exceeded with url: / (Caused by N
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
ns1.usa.cloudns.ions2.usa.cloudns.ions25.webrserver.comns26.webrserver.comLocation describes the IP network.
ca6f3f704da70a4aa5b0fa4becbef6acdf4f80c3f7276bb86e2f3da02e600015shop.sewtexbd.comwww.shop.sewtexbd.comwww.zawadgroup.com.sewtexbd.comwww.zawadshop.com.sewtexbd.comzawadgroup.comSaved certificate metadata. Certificate dates without a timezone are shown as stored. Transport encryption does not establish that the site is trustworthy.
Google PageSpeed Insights — mobile performance audit of duplicate-disabled-12421.invalid · checked Mar 2, 2026
13 recorded events. These records describe collected evidence, outgoing notifications and publication; they do not confirm a complete investigation or a takedown.
We scan suspicious URLs, inspect public results and send evidence through the appropriate abuse-reporting channels. The dated events above show what is recorded for this domain. The directory below explains the wider workflow.
Capture the rendered page, requests and visible infrastructure.
Compare the available engine results and retain the analysis timestamp.
Check whether Google currently lists the URL as unsafe.
Inspect a public scan and its recorded network and classification data.
Look for indicator references and related community intelligence.
Compare archived captures and preserve historical context.
Look for matching indicators and associated threat records.
Inspect certificate records and related hostnames.
Compare security resolver responses and record observed blocking.
Inspect the public DNS, TLS, HTTP and technology surface.
Security services used for scanning, reputation checks and reporting are listed below. A service being listed is not evidence that it received, accepted or acted on this particular domain. Recorded submissions appear in the notification history above.
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.
Template-based draft · optional AI wording assistance requires separate consent
Saklanan engelleme listesi, WHOIS, DNS ve genel tarama kanıtlarını kullanarak tehdit analizi
Şimdi TaraŞüpheli alan adlarını tehdit veritabanımıza bildirin — topluluğu koruyun
BildirSon kimlik avı raporları ve gözlemlenen kullanılabilirlik değişiklikleri
İzleCanlı tehditleri izleyin veya bunun yanlış bir uyarı olduğunu düşünüyorsanız bu kayda itiraz edin