vojoki[.]icu
“Messenger”
Kaydedilmiş tespit
Gizleme uyarısı
- Gizleme türü
content_divergence- Gizleme puanı
- 1/6
Kanıt özeti
This domain, vojoki.icu, is flagged as an active phishing site targeting users of the Messenger platform. Analysis indicates the site is designed to mimic legitimate Messenger login interfaces, aiming to harvest user credentials through fraudulent input forms. The threat type is classified as generic_phishing with an elevated risk level, suggesting a broad but targeted approach to credential theft. No specific drainer kit signatures have been identified at this stage, though the infrastructure aligns with common phishing toolkits used in credential harvesting campaigns. Infrastructure analysis reveals the domain was registered on June 24, 2024, through NICENIC INTERNATIONAL GROUP CO., LIMITED, a registrar frequently associated with high-risk domains. The domain resolves to the IP address 104.21.30.76, which is part of a content delivery network known for obfuscating malicious infrastructure. As of the latest scan, 14 out of 95 security vendors on VirusTotal have flagged vojoki.icu as malicious, indicating moderate but growing detection. The SSL certificate is issued by Google Trust Services, a tactic often employed to lend an air of legitimacy to phishing sites. No entries were found in Google Safe Browsing at the time of analysis, though this does not preclude the domain from being malicious. The site remains active and poses an ongoing risk to users who may be deceived by its Messenger branding. Immediate response actions include blocking the domain at the DNS level and flagging it for takedown through the registrar. Users who may have interacted with the site are advised to reset their credentials using multi-factor authentication and monitor for unauthorized account activity. Despite partial detection by security vendors, the domain's use of a content delivery network and legitimate SSL certificate complicates mitigation efforts, leaving residual risk until full takedown is achieved.
Gönderilen kanıt anlık görüntüsü
- Gönderildi
- Kayıt defteri kayıtları
- 1
- Vaka kimliği
PD-20260628-2C49BC- PDF belgesi
- PDF kanıtı
Kanıtın tam metni
Policy Violations: “Services may be used only for lawful purposes… fraud, abuse and illegal activity prohibited. Violations may result in immediate suspension.” + dedicated abuse handling and takedown
Applicable Laws: Crimes Ordinance Cap.200 (Fraud), Theft Ordinance Cap.210 §16A (fraud by deception), Personal Data (Privacy) Ordinance Cap.486
Data Coverage
Ağ Güvenliği İstihbaratı
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Hagezi Threat Feed | vojoki.icu |
malicious | Sinkholed |
| OpenDNS | vojoki.icu |
phishing | Phishing Block |
| Cloudflare DNS | vojoki.icu |
malicious | Sinkholed |
| DNS4EU | vojoki.icu |
malicious | Sinkholed |
Tehdit Müdahale Pipeline
Engelleme listesi kapsamı
10 izlenen harici kaynak · kayıtlı anlık görüntü 11.08.2026
Kaydedilmiş sonuç kanıtı
Sonuç ve kaldırma ilişkilendirmesi
- Sonuç
dns_inactive- Neden
dns_nxdomain- Güven
- 80%
- İlk gözlem
- Son gözlem
Tahmini erişilememe
Erişilemezliğe kadar geçen süre: 0 hKanıt SHA-256 d0b7046e8c2f
Tespit zaman çizelgesi
-
VirusTotal
None → 14
-
Erişilebilirlik
İlk kayıtlı değer: DNS etkin değil
f93a11f87e4d -
Erişilebilirlik
DNS etkin değil → Bilinmiyor
9530346dcef2 -
Erişilebilirlik
Bilinmiyor → DNS etkin değil
2a7f8bc7576d -
Erişilebilirlik
DNS etkin değil → Bekletiliyor
e099d1d6ab74 -
Erişilebilirlik
Bekletiliyor → DNS etkin değil
f52d526b76a1 -
Erişilebilirlik
DNS etkin değil → Bilinmiyor
b5c8fa293bd6 -
Erişilebilirlik
Bilinmiyor → DNS etkin değil
6dfe9145995c -
Erişilebilirlik
DNS etkin değil → Bilinmiyor
ab871307d526 -
Erişilebilirlik
Bilinmiyor → Bekletiliyor
0a0835c5be31
Tümünü göster (2)
-
Erişilebilirlik
Bekletiliyor → Bilinmiyor
988ed0b23af8 -
Erişilebilirlik
Bilinmiyor → DNS etkin değil
d0b7046e8c2f
Topluluk raporları
0 topluluk üyesi tarafından bildirildi; ilk görülme 28.06.2026
- Bildirilen benzersiz URL’ler
- 1
Kaydedilen görüntü
Etki Alanı Analizi
Teknik ayrıntılarDNS, TLS adları ve zaman damgaları
SHORTDOT BÖLGESİ · KAMUYA AÇIK KANIT
.icu
ShortDot zone evidence
ShortDot zone evidence
The linked repository preserves daily zone observations across seven ShortDot-operated TLDs, including registration volume and abuse-related indicators. This registry context is supporting background and is not an independent detection for the domain in this report.
ICANN OVERSIGHT
Akreditasyon ve RAA bağlamı
Akreditasyon ve RAA bağlamı
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Teknolojiler
3 yüksek güvenli teknoloji belirlendi
VirusTotal Analizi
Site Performans Analizi
Google PageSpeed Insights — mobile performance audit of vojoki.icu · checked Jun 28, 2026
Bu Siteden Etkilendiniz mi?
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.
Herhangi Bir Alan Adını Kontrol Et
Saklanan engelleme listesi, WHOIS, DNS ve genel tarama kanıtlarını kullanarak tehdit analizi
Şimdi TaraOltalama Olayını Bildir
Şüpheli alan adlarını tehdit veritabanımıza bildirin — topluluğu koruyun
BildirCanlı Tehdit Akışı
Son kimlik avı raporları ve gözlemlenen kullanılabilirlik değişiklikleri
İzleGelişmelerden Haberdar Olun, Güvende Kalın
Canlı tehditleri izleyin veya bunun yanlış bir uyarı olduğunu düşünüyorsanız bu kayda itiraz edin