eudarkhan[.]mn
“MDG188 : Innovation & Entrepreneurship Hub Mdg 188 Login From EUDarkhan.mn”
证据摘要
The domain eudarkhan.mn was observed on July 12, 2026 delivering a credential phishing campaign. The site presents a login interface titled “MDG188 : Innovation & Entrepreneurship Hub Mdg 188 Login From EUDarkhan.mn”, matching the known phishing lure. Threat intelligence classifies the activity as generic_phishing with a high risk rating and an active status.
The domain was registered on March 29, 2026 through Datacom Co., Ltd. It resolves to the IPv4 address 202.131.4.3, which is geolocated to Mongolia and is owned by DataCom Co., Ltd. Authoritative nameservers ns1.dns.mn, ns2.dns.mn, ns3.dns.mn, and ns4.dns.mn resolve the domain, and the MX records point to us2.mx1.mailhostbox.com with priority 100. The site serves content over HTTPS using a Let’s Encrypt R13 certificate, and HTTP requests return a 200 status code.
Web application fingerprinting reveals a WordPress stack backed by MySQL and PHP, hosted on Apache HTTP Server. Front‑end components include Slider Revolution, jQuery, and jQuery Migrate, indicating a typical content‑management system that can be weaponised for credential harvesting. No additional scripts or obfuscation were detected beyond the login page.
VirusTotal scans have flagged the domain in 4 out of 95 security vendor checks, and the domain appears on a single security blocklist. Gridinsoft assigns a trust score of 0 out of 100, and PhishDestroy has already blocked the site. These independent indicators converge on a high confidence that the domain is being used for credential phishing, consistent with the observed page title and infrastructure.
Defenders should block eudarkhan.mn at the DNS and firewall layers, enforce TLS inspection to capture credential submissions, and monitor for outbound connections to the IP 202.131.4.3. Email filters should be updated to reject messages originating from the listed MX host. User education campaigns must warn personnel about the specific “MDG188” login lure to reduce successful credential theft.
已提交证据快照
- 已发送
- 台账记录
- 1
- 案件 ID
PD-20260329-BC8CBE- 已捕获页面标题
- MDG188 : Innovation & Entrepreneurship Hub Mdg 188 Login From EUDarkhan.mn
- PDF 文件
- PDF 证据
完整证据文本
Illegal Activities: Active phishing operation targeting victims
Fraud & Deception: Impersonation of legitimate services
Identity Theft: Collection of credentials under false pretenses
Applicable Laws (AU):
Criminal Code Act 1995 - Division 474
Criminal Code Act 1995 - Division 477
Privacy Act 1988
Australian law criminalizes telecommunications and computer-based fraud.
Action Required: This evidence-backed report demonstrates clear violations requiring suspension per your policies. Continued hosting exposes your organization to regulatory scrutiny and potential legal liability.
Data Coverage
网络安全情报
威胁响应 Pipeline
阻止列表覆盖
监控中的外部数据源 10 个 · 已存快照 2026年8月10日
检测时间线
-
VirusTotal
0 → 4
VirusTotal 分析
网站性能分析
Google PageSpeed Insights — mobile performance audit of eudarkhan.mn · checked Jun 26, 2026
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。
检查任意域名
使用存储的阻止列表、WHOIS、DNS 和公共扫描证据进行威胁分析
立即扫描举报网络钓鱼
将可疑域名提交至我们的威胁数据库——保护社区
报告实时威胁动态
最近的网络钓鱼报告和观察到的可用性变化
监控