Перейти до звіту про безпеку
⚠️
Цей домен було позначено як шкідливий
Системи безпеки повідомляють про виявлення: 17. Будьте дуже обережні — не вводьте облікові дані чи особисту інформацію.
Безпека домену та аналіз загроз

dc[.]crsorgi[.]gov[.]in[.]verifyy[.]in

“CRS Portal (crsorgi.gov.in) - Birth & Death Certificate | Print Portal | DC CRS Login | CRS BIRTH P…”

Загрозливий вердикт Критичний 95/100 оцінка доказів
Доступність Контент недоступний Вміст був недоступний під час останнього спостереження
Виявлення VirusTotal: 17/91 URLQuery threat systems: 5 alerts Тип шахрайства: Credential Phishing
17.06.2026 1 Report Sent CDN
Огляд звіту

dc.crsorgi.gov.in.verifyy.in — Контент недоступний. Тип шахрайства: Credential Phishing. Зведення доказів: VirusTotal 17/91 (ADMINUSLabs, Bfore.Ai PreCrime, BitDefender, CRDF, CyRadar); URLQuery 5 alerts; CF Radar malicious; PhishDestroy score 95/100. Реєстратор: GoDaddy.

Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.

Зведення доказів
КРИТИЧНИЙ
Посилання
EF504D39
Оцінка
95/100

This domain, dc.crsorgi.gov.in.verifyy.in, poses as the official Civil Registration System (CRS) portal for birth and death certificates in India. Analysis indicates it is a credential phishing site designed to harvest login credentials from users attempting to access legitimate government services. The site uses a deceptive page title, CRS Portal (crsorgi.gov.in) - Birth & Death Certificate | Print Portal | DC CRS Login | CRS BIRTH PORTAl, to trick visitors into believing they are interacting with the authentic crsorgi.gov.in portal. The threat extends beyond simple impersonation, as the site employs SSL encryption (Let's Encrypt) to appear legitimate and evade casual detection. Infrastructure analysis reveals multiple red flags confirming its malicious nature. The domain was registered through GoDaddy on March 11, 2026, an unusual future date that may indicate an attempt to evade immediate scrutiny or automated detection systems. As of the latest scan, 17 out of 95 security vendors on VirusTotal flag this domain as malicious, with detection names including phishing, fraud, and credential theft. The domain resolves to the IP address 54.39.160.85 and is blocked by three security blocklists, including PhishDestroy, OISD, and Maltrail. Additional technical indicators include the use of Bootstrap, Cloudflare, jQuery, and other common web technologies, which are often leveraged to create convincing replicas of legitimate sites. Users who visited dc.crsorgi.gov.in.verifyy.in should assume their credentials were compromised. Immediate action is required: change passwords for any accounts accessed after visiting the site, particularly those tied to government services or sensitive personal data. Enable multi-factor authentication (MFA) on all critical accounts to mitigate the risk of unauthorized access. Monitor financial and government service accounts for unusual activity, and report any suspected identity theft to the appropriate authorities. If login credentials for crsorgi.gov.in or related services were entered, contact the official CRS portal support team to secure the account. Avoid reusing passwords across multiple platforms, and consider using a password manager to generate and store unique credentials. This domain has been taken offline, but similar threats may emerge; always verify the URL and SSL certificate before entering sensitive information.

VirusTotal
VirusTotal
17 det.
URLQuery
URLQuery
5 threat alerts
CF Radar
Шкідливий
URLScan
URLScan
Сертифікат TLS
Let's Encrypt / YR1 16d
Вік
5 mo
Зафіксований статус
Контент недоступний
PhishDestroy
DestroyList
У списку
Reports Sent
1
Обсяг даних VirusTotal 17 / 91 URLQuery 5 threat-system alerts PhishStats не перевірено OTX no community references CF Radar provider verdict: malicious URLScan capture збережений звіт URLScan verdict Аналіз завершено Блокування DNS не перевірено TLS valid certificate, 16d WHOIS 5 mo old Знімок екрана 3 captures · 3 sources Ланцюжок перенаправлень не досліджено
Розвіддані з мережевої безпеки
Threat Detection Systems 5 alerts
Detection System Indicator Verdict Alert
Cloudflare DNS dc.crsorgi.gov.in.verifyy.in malicious Sinkholed
OpenDNS dc.crsorgi.gov.in.verifyy.in phishing Phishing Block
DNS4EU dc.crsorgi.gov.in.verifyy.in malicious Sinkholed
Hagezi Threat Feed dc.crsorgi.gov.in.verifyy.in malicious Sinkholed
Quad9 DNS dc.crsorgi.gov.in.verifyy.in malicious Sinkholed
CF Cloudflare Radar Verdict Шкідливий
Phishing Malware

Процес реагування на загрози Pipeline

Відкриття
Checks
Reports
Доступність
13/13
Sent Report Recorded
Stored sent-report record for registrar GoDaddy, hosting provider, 2 abuse contacts
abuse@ovh.caabuse@godaddy.com
17.06.2026

Статус у публічних блоклистах

Збережений знімок

Аналітика доменів

Домен
URLScan Verdict Аналіз завершено score 0 report ↗
Сервер / ASN cloudflare · AS16276 OVH OVH SAS, FR
IP Context Cloudflare shared edge origin IP hidden Репутація Edge-IP не пов’язана з цим доменом.
Registrar (base domain) GoDaddy IN(IN)
Контакт для скаргabuse@ovh.ca, abuse@godaddy.com
IP-адреса 54.39.160.85 CDN
ГеолокаціяCA Beauharnois, CA
МережаAS16276 · OVH SAS
Зворотний пошук IPviewdns.info → rapiddns.io →
Початкова IP-адреса прихована за проксі CDN. Результати зворотного IP для крайової адреси містять непов’язаних орендарів; для пошуку джерела потрібен пасивний DNS або дані прозорості сертифіката.
Registration (base domain)verifyy.in · Створено 11.03.2026 (160d) Expires 11.03.2027
Час до першої недоступності 28h
Що ми враховуємо Час, що минув від першого збереженого звіту про порушення до першого спостереження, що вміст був недоступний. Це не встановлює причину.
Що містить кожен звіт Збережені записи вихідних звітів можуть посилатися на докази, доступні на той час, наприклад вердикти постачальників, реєстраційні дані, деталі хостингу, класифікації або знімки екрана. Ця сторінка не визначає точного доставленого корисного навантаження, квитанції, підтвердження чи дії одержувача.
Технічні деталіDNS, SAN-адреси SSL, мітки часу
Вперше виявлено17.06.2026
DOM Analysisanalyzed 17.06.2026score 88/100
IoC Extractionscanned 01.08.20260 wallet · 0 Telegram IoCs
Submitted URLhttp://dc.crsorgi.gov.in.verifyy.in/
Сервери іменreese.ns.cloudflare.comvita.ns.cloudflare.com
TLS Fingerprint
TLS Observationvalid from 06.06.2026scanned 17.06.2026
TLS SAN Domainsverifyy.in
Case ID
Заголовок сторінки
CRS Portal (crsorgi.gov.in) - Birth & Death Certificate | Print Portal | DC CRS Login | CRS BIRTH PORTAl
Сертифікат TLS
Valid transport encryption · Виданий Let's Encrypt / YR1 · valid for 16 days
Технології · 11 identified
Bootstrap
UI frameworks

Bootstrap is a free and open-source CSS framework directed at responsive, mobile-first front-end web development. It contains CSS and JavaScript-based design templates for typography, forms, buttons, navigation, and other interface components.

getbootstrap.com 100% впевненості
Cloudflare
CDN

Cloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.

www.cloudflare.com 100% впевненості
Unpkg
CDN

Unpkg is a content delivery network for everything on npm.

unpkg.com 100% впевненості
SweetAlert2
JavaScript libraries

SweetAlert2 is a JavaScript library that provides customisable, visually appealing, and responsive alert and modal dialog boxes for web applications.

sweetalert2.github.io 100% впевненості
SweetAlert
JavaScript libraries

SweetAlert is a JavaScript library that provides alternative alert and modal dialog boxes for web applications, with customisable features, aiming to improve the user interface of the default browser dialogs.

sweetalert.js.org 100% впевненості
jsDelivr
CDN

JSDelivr is a free public CDN for open-source projects. It can serve web files directly from the npm registry and GitHub repositories without any configuration.

www.jsdelivr.com 100% впевненості
jQuery
JavaScript libraries

jQuery is a JavaScript library which is a free, open-source software designed to simplify HTML DOM tree traversal and manipulation, as well as event handling, CSS animation, and Ajax.

jquery.com 100% впевненості
Google Hosted Libraries
CDN

Google Hosted Libraries is a stable, reliable, high-speed, globally available content distribution network for the most popular, open-source JavaScript libraries.

developers.google.com 100% впевненості
FancyBox
JavaScript libraries

FancyBox is a tool for displaying images, html content and multi-media in a Mac-style 'lightbox' that floats overtop of web page.

fancyapps.com 100% впевненості
cdnjs
CDN

cdnjs is a free distributed JS library delivery service.

cdnjs.com 100% впевненості
HTTP/3
Miscellaneous

HTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.

httpwg.org 100% впевненості
Detected via Cloudflare Radar · Wappalyzer engine
Поскаржитися на цей домен Надішліть докази та допоможіть захистити інших

Аналіз VirusTotal

17 / 91 постачальників безпеки позначили цей домен
View on VT
Last analyzed Previous stored snapshot: 16 detections
ADMINUSLabs
Bfore.Ai PreCrime
BitDefender
CRDF
CyRadar
ESET
Forcepoint ThreatSeeker
Fortinet
G-Data
Gridinsoft
Lionic
OpenPhish
Seclookup
SOCRadar
Sophos
VIPRE
Аналіз продуктивності сайту

Google PageSpeed Insights — mobile performance audit of dc.crsorgi.gov.in.verifyy.in · checked Jun 25, 2026

67
Needs Work
Performance
FCP
5.3s
First Contentful Paint
LCP
5.32s
Largest Contentful Paint
CLS
0.019
Cumulative Layout Shift
TBT
0ms
Total Blocking Time
SI
5.3s
Speed Index
Powered by Google PageSpeed Insights · Mobile strategy · Scores: 90-100 Good 50-89 Needs Work 0-49 Poor

Докази та зовнішні звіти

Submitted Evidence Snapshot
Sent: Ledger records: 1 Case ID: PD-20260617-BEDAD1 Recipient: abuse@ovh.ca
Page title stored with report: Problem loading page
URLScan evidence VirusTotal evidence URLQuery evidence Screenshot 593.1 KB
Blocklist hits included with submission: OpenPhish

Чи вплинув на вас цей сайт?

If credentials were compromised, report immediately. Do not engage with recovery scammers.

Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.

Європол
Знайдіть офіційний канал звітності для вашої країни ЄС
National police directory
Остерігайтеся шахраїв, які обіцяють повернути втрачені кошти! Злочинці можуть знову зв’язатися з жертвами, видаючи себе за слідчих, адвокатів або агентів із відновлення. Не сплачуйте авансових зборів і не діліться обліковими даними. Дізнайтеся більше про шахрайство у сфері відшкодування збитків →

Зверніться до місцевих органів влади

Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.

Довідник 97 країн
Чернетка за допомогою штучного інтелекту — деталі інциденту обробляються постачальником штучного інтелекту Перегляньте та подайте його самостійно

Перевірити будь-який домен

Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування

Сканувати зараз

Повідомити про фішинг

Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту

Повідомити

Потокова стрічка про загрози

Останні звіти про фішинг і помічені зміни доступності

Відстежувати

Будьте в курсі подій, дбайте про свою безпеку

Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога

Потокова стрічка про загрози Оскаржити це оголошення
HTML · IFRAME

Вбудувати цей звіт

Поділіться цією інформацією про загрози на своєму веб-сайті або в блозі

embed.html
<iframe
  src="https://phishdestroy.io/uk/embed/domain/dc.crsorgi.gov.in.verifyy.in"
  title="PhishDestroy threat report for dc.crsorgi.gov.in.verifyy.in"
  width="100%" height="320"
  loading="lazy"
  referrerpolicy="no-referrer"
  sandbox="allow-same-origin allow-popups allow-popups-to-escape-sandbox"
  style="border:0;border-radius:12px;max-width:100%"
></iframe>