Notification and current-status evidence
The sent-report ledger records the first outgoing report at .
The recorded recipient is abuse@dynadot.com.
The latest stored availability evidence still shows the domain reachable; 2 months has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
mon-paiement-cpam[.]info
“Plesk Obsidian 18.0.78”
mon-paiement-cpam.info — Неперевірений. Тип шахрайства: Generic Phishing. Зведення доказів: VirusTotal 17/91 (alphaMountain.ai, BitDefender, Chong Lua Dao, Cluster25, CRDF); URLQuery 5 alerts; PhishDestroy score 95/100. Реєстратор: Dynadot.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
PhishDestroy has identified mon-paiement-cpam.info as a high-risk phishing domain currently active and targeting users with a fraudulent login page designed to steal credentials. The site impersonates the French health insurance organization CPAM (Caisse Primaire d'Assurance Maladie), tricking victims into entering sensitive personal and financial information under the guise of payment management. This is a classic credential harvesting attack, where the stolen data can be used for identity theft, unauthorized transactions, or sold on dark web markets.
The evidence against this domain is overwhelming. VirusTotal analysis shows that 12 out of 95 security vendors flag mon-paiement-cpam.info as malicious, a clear indicator of its dangerous nature. The domain was registered on June 15, 2026, through Dynadot Inc, a registrar often abused for phishing operations. Despite being a relatively new domain, it already appears on 1 security blocklist, and its SSL certificate, issued by Let's Encrypt, gives it a false veneer of legitimacy. The site resolves to IP address 85.121.176.173 and currently displays a Plesk Obsidian 18.0.78 default page, suggesting it may be under construction or used for multiple phishing campaigns.
If you have visited mon-paiement-cpam.info or entered any information, take immediate action. Change the passwords for any accounts you may have used, especially if you reused credentials. Contact your bank and credit card companies to monitor for fraudulent transactions. Enable two-factor authentication on all important accounts. Report the incident to local authorities and consider placing a fraud alert on your credit file. Always verify the legitimacy of official websites by typing the URL directly into your browser rather than clicking links from emails or messages. For more information on phishing threats, visit PhishDestroy.
Розвіддані з мережевої безпеки
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| OpenDNS | mon-paiement-cpam.info |
phishing | Phishing Block |
| Hagezi Threat Feed | mon-paiement-cpam.info |
malicious | Sinkholed |
| DNS4EU | mon-paiement-cpam.info |
malicious | Sinkholed |
| Cloudflare DNS | mon-paiement-cpam.info |
malicious | Sinkholed |
| DigiCert UltraDNS | mon-paiement-cpam.info |
malicious | Sinkholed |
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Збережений знімок
Аналітика доменів
Технічні деталіDNS, SAN-адреси SSL, мітки часу
ICANN OVERSIGHT
Акредитація та контекст RAA
Акредитація та контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Аналіз VirusTotal
Докази та зовнішні звіти
PD-20260618-634128 Recipient: abuse@dynadot.com Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога