Notification and current-status evidence
The sent-report ledger records the first outgoing report at .
The recorded recipient is 6opw59924@ningqi.live.
The latest stored availability evidence still shows the domain reachable; 1 month has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
helloworld-apps[.]com[.]cn
Перевірка домену helloworld-apps.com.cn на фішинг і безпеку
“Kraken交易平台-安心购买加密货币”
helloworld-apps.com.cn — Неперевірений. Уособлення бренду: Kraken; Тип шахрайства: Brand Impersonation. Зведення доказів: VirusTotal 2/91 (Fortinet, Gridinsoft); Spamhaus DBL_PHISH; 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 78/100. Реєстратор: Dominet (HK).
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
Analysis of the domain helloworld-apps.com.cn indicates a confirmed brand impersonation targeting Kraken, a cryptocurrency exchange. The domain was registered on May 6, 2026, through Dominet (HK) Limited and is currently offline. Infrastructure analysis reveals hosting on Alibaba (US) Technology Co., Ltd. (AS45102) in Hong Kong, resolving to IP address 47.239.173.17. The domain uses Alibaba's nameservers (ns7.alidns.com and ns8.alidns.com) and a Let's Encrypt SSL certificate issued under the YR2 intermediate.
The page title, 'Kraken交易平台-安心购买加密货币,' explicitly references Kraken and cryptocurrency trading, aligning with the scam type classified as brand impersonation. Detection by three security blocklists—PhishDestroy, MetaMask, and SEAL—further corroborates its malicious classification. VirusTotal reports two out of ninety-one security vendors flagging the domain, though this limited detection does not diminish the elevated risk level. While the domain is currently offline, its infrastructure and registration details remain relevant for defensive measures.
Defenders should treat this domain as a confirmed threat, blocking resolution at the DNS level and monitoring for re-emergence under the same or similar infrastructure. The use of Alibaba's hosting and DNS services, combined with a recently issued SSL certificate, suggests a deliberate attempt to appear legitimate. No evidence of a phishing kit or additional technical artifacts is available at this time, but the domain's alignment with known impersonation tactics warrants continued scrutiny.
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Аналіз VirusTotal
Докази та зовнішні звіти
PD-20260624-40B5AC Recipient: 6opw59924@ningqi.live Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога