fakebillx[.]org
“Fakebillx - Fake Bill Chuyển Khoản nhanh chóng tự động”
Зведення доказів
The domain fakebillx.org was identified as a brand impersonation threat specifically targeting Google, though it has since been taken offline. This site was designed to deceive users by presenting itself as a fake bill transfer service, as indicated by its page title "Fakebillx - Fake Bill Chuyển Khoản nhanh chóng tự động," which translates to a Vietnamese-language fake payment automation scheme. The domain's primary objective was to steal credentials or financial information by masquerading as a legitimate Google-related service, a classic tactic in phishing campaigns aimed at exploiting trust in major brands.
Technical analysis reveals that fakebillx.org was registered on November 22, 2025, through Cloudflare, Inc., a common registrar for malicious domains due to its privacy features. The domain resolved to IP address 188.114.96.3 and was equipped with an SSL certificate issued by Google Trust Services under the WE1 designation, which added a false veneer of legitimacy. On VirusTotal, only 1 out of 95 security vendors flagged the domain as malicious, and it appeared on just 1 security blocklist, indicating that it evaded many detection systems prior to being taken down. The low detection rate and relatively recent creation date suggest the threat was both targeted and short-lived.
Now that the domain has been taken offline, the immediate risk to users is minimized, but the incident underscores the importance of vigilance. PhishDestroy recommends that organizations and individuals monitor for similar domains and educate users about verifying payment requests, especially those involving brand impersonation. Users should always check URLs carefully, avoid clicking on unsolicited links, and report any suspicious sites to security teams. While this specific threat is neutralized, the tactics employed here could be reused, so ongoing awareness and robust email filtering remain critical defenses.
Data Coverage
Сигнали безпеки
Процес реагування на загрози Pipeline
Перевірка за блок-листами
10 зовнішніх джерел під наглядом · знімок від 12.08.2026
Хронологія виявлення
-
VirusTotal
1 → 2
Збережений знімок
Аналітика доменів
Технічні подробиціDNS, імена TLS і часові мітки
ICANN OVERSIGHT
Акредитація та контекст RAA
Акредитація та контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Аналіз VirusTotal
Аналіз продуктивності сайту
Google PageSpeed Insights — mobile performance audit of fakebillx.org · checked Mar 2, 2026
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога