Notification and current-status evidence
The sent-report ledger records the first outgoing report at .
The recorded recipient is abuse@shinjiru.com.my.
The latest stored availability evidence still shows the domain reachable; 3 months has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
glbiochem[.]net
glbiochem.net için kimlik avı ve güvenlik kontrolü
“GL Biochem (Shanghai) Ltd. — World's Leading Peptide & Amino Acid Manufacture...”
glbiochem.net — Bilinen son aktif (HTTP 200). Dolandırıcılık türü: Generic Phishing. Kanıt özeti: VirusTotal 6/91 (alphaMountain.ai, CRDF, Fortinet, Gridinsoft, SOCRadar); Spamhaus DBL_SPAM; PhishDestroy score 88/100. Kayıt kuruluşu: Fewmoretaps OU d/b/a T….
Özgün adli kaydı korumak için aşağıdaki ayrıntılı PhishDestroy AI analizi İngilizce bırakılmıştır.
The domain glbiochem.net has been identified as a phishing site specifically targeting customers of GL Biochem (Shanghai) Ltd., a legitimate peptide and amino acid manufacturer established in 1998. Analysis indicates this infrastructure was designed to impersonate the official GL Biochem brand, likely for fraudulent order processing, credential harvesting, or financial deception. The site is currently offline, though prior activity suggests it was operational for malicious purposes. Infrastructure analysis reveals multiple high-risk indicators. The domain was registered on March 10, 2026, through Fewmoretaps OU d/b/a Trustname.com, a registrar frequently associated with suspicious registrations. It resolves to the IP address 101.99.94.39 and has been flagged by 1 security blocklist. Despite its recent creation, the domain has not yet been detected by any of the 95 security vendors on VirusTotal. Trust scores from Gridinsoft and Scamadviser are critically low at 3/100 and 1/100, respectively. The site employed a Let's Encrypt SSL certificate and was built using Node.js, Ubuntu, Nginx, and Express technologies, which are common in both legitimate and malicious web applications. Current evidence suggests this phishing infrastructure was taken offline following detection by PhishDestroy. However, the domain remains registered and could be reactivated or repurposed. Organizations and individuals are advised to block the domain and associated IP address (101.99.94.39) at the network level. Customers of GL Biochem should verify all communications through official channels and avoid interacting with unsolicited emails or websites claiming to represent the company. Monitoring for similar domains registered through Fewmoretaps OU or resolving to the same IP range is recommended to preempt further fraud attempts.
Güvenlik Sinyalleri
Ağ Güvenliği İstihbaratı Registrar context
Tehdit Müdahale Pipeline
Genel Engelleme Listesi Durumu
Kaydedilen görüntü
Etki Alanı Analizi
Teknik ayrıntılarDNS, SSL SAN’ları, zaman damgaları
ICANN OVERSIGHT
Akreditasyon ve RAA bağlamı
Akreditasyon ve RAA bağlamı
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Teknolojiler · 4 identified
Node.js is an open-source, cross-platform, JavaScript runtime environment that executes JavaScript code outside a web browser.
nodejs.org %100 güvenUbuntu is a free and open-source operating system on Linux for the enterprise server, desktop, cloud, and IoT.
www.ubuntu.com %100 güvenNginx is a web server that can also be used as a reverse proxy, load balancer, mail proxy and HTTP cache.
nginx.org %100 güvenExpress is a web application framework for Node.js, released as free and open-source software under the MIT License. It is designed for building web applications and APIs.
expressjs.com %100 güvenVirusTotal Analizi
Site Performans Analizi
Google PageSpeed Insights — mobile performance audit of glbiochem.net · checked Jun 26, 2026
Kanıtlar ve Dış Raporlar
“The wallet address TDzS9Se8kgJuDZ1tVXkgNpAErYed3evgYy is used by a fraudulent website glbiochem.net. This site is a malicious impersonation of the legitimate company GL Biochem (Shanghai) Ltd (glschina.com). The scammers use the .net domain to trick customers into sending cryptocurrency payments for products that are never shipped. This domain was registered on March 10, 2026, and is hosted by Vercel (IP: 216.150.1.1). I have reported this incident to the Australian Federal Police (ReportCybe”
PD-20260424-D22DCA Recipient: abuse@shinjiru.com.my Bu Siteden Etkilendiniz mi?
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.
Herhangi Bir Alan Adını Kontrol Et
Saklanan engelleme listesi, WHOIS, DNS ve genel tarama kanıtlarını kullanarak tehdit analizi
Şimdi TaraOltalama Olayını Bildir
Şüpheli alan adlarını tehdit veritabanımıza bildirin — topluluğu koruyun
BildirCanlı Tehdit Akışı
Son kimlik avı raporları ve gözlemlenen kullanılabilirlik değişiklikleri
İzleGelişmelerden Haberdar Olun, Güvende Kalın
Canlı tehditleri izleyin veya bunun yanlış bir uyarı olduğunu düşünüyorsanız bu kayda itiraz edin