Threat catalog
Search saved risk checks
Find domains and senders already saved from a risk check. Each result has a public page Google can index.
Inventory
17
Results
17 matches
- 01
i***@sfrclak.com
View indicators
- Malicious Packages: axios@1.14.1, axios@0.30.4, plain-crypto-js@4.2.1
- C2 Server: sfrclak.com (IP: 142.11.206.73)
- File Indicators: macOS File /Library/Caches/com.apple.act.mond; Windows File %PROGRAMDATA%\wt.exe; Linux File /tmp/ld.py
Mar 31, 2026
95% confidence
- 02
i***@wa.org-etcxh.bond
View indicators
- Suspicious domain: 'wa.org-etcxh.bond' suggesting potential phishing intent
- Domain structure: complex with 'etcxh.bond', typical of malicious domains
- Missing DNS records: lack of MX and TXT records indicating fraudulent configuration
- Domain impersonation: attempting to mimic Washington DMV through altered domain
Feb 28, 2026
90% confidence
- 03
p***@events.1haoxi.com
View indicators
- Domain age: Newly registered domain 'events.1haoxi.com' with no DNS records raises suspicion.
- Lack of DNS records: No A, MX, TXT, NS, or CNAME records found for 'events.1haoxi.com', indicating a potentially fraudulent domain.
- Unsolicited job offer: Generic and vague email content claiming to offer high compensation for part-time work is a common phishing tactic.
- Urgency manipulation: Requesting immediate action by asking recipients to text 'More Info' to an unknown number is a classic scam approach.
Jan 13, 2026
90% confidence
- 04
l***@h.lushanotice.com
View indicators
- Unusual domain structure: subdomain 'h.lushanotice.com' lacks credibility.
- Weak anti-spoofing policies: SPF record includes 'mailgun.org' but lacks strict enforcement ('~all').
- Absence of DMARC policy enforcement: DMARC set to 'p=none', indicating vulnerability.
- Lack of SSL certificate raises concerns about legitimacy.
- Content title: 'Personal Information Notice' commonly associated with phishing tactics.
Jan 6, 2026
85% confidence
- 05
i***@wa.gov-vja.bond
View indicators
- impersonation: The sender uses '[sender display name]' instead of '[sender name]'
- urgency: The message explicitly states '[time pressure language found]'
- suspicious_url: The URL 'https://wa.gov-vja.bond/dol?var=CBiacvjacx' is visible
- domain impersonation: 'wa.gov-vja.bond' mimicking legitimate government domains
- lack of MX records indicates potential phishing
- uncommon TLD '.bond' raises suspicion
Dec 11, 2025
85% confidence
- 06
n***@e-zpassny.hsmv-ay.work
View indicators
- Impersonation: Email from sender 'noreply@e-zpassny.hsmv-ay.work' mimics legitimate service branding.
- Urgency manipulation: Message demands immediate payment 'before enforcement occurs' to incite fear.
- Suspicious URL: Links to 'https://e-zpassny.hsmv-ay.work/' which uses a generic domain.
- Generic display name: Sender details lack specific branding, indicating possible phishing.
Oct 15, 2025
90% confidence
- 07
i***@e-zpassny.adgpay.cc
View indicators
- Urgency: 'Suspension effective October 16th'
- Suspicious URL: 'https://e-zpassny.adgpay.cc/us'
- Domain impersonation: 'e-zpassny.adgpay.cc' masquerading as EZPass
- Social engineering: 'Go to a toll booth and be charged a 35% service fee'
Oct 15, 2025
95% confidence
- 08
p***@uncsds-summit.org
View indicators
- Domain age: Newly registered domain (August 4, 2025) indicates potential phishing
- SPF record includes third-party domains (mailbaby.net), suggesting email forgery
Oct 12, 2025
85% confidence
- 09
n***@szjuanbai.xyz
View indicators
- Domain age: Newly registered domain (September 4, 2023) indicates potential phishing
- Lack of A records for 'szjuanbai.xyz' suggests suspicious intent
- Absence of standard DNS records (TXT, CNAME)
- Domain registration with Gname.com, known for spam or phishing associations
Oct 12, 2025
85% confidence
- 10
n***@rnicrosoft.com
View indicators
- Domain impersonation: 'rnicrosoft.com' closely resembles 'microsoft.com'
- Known malicious patterns: The use of 'noreply' in the email address suggests an intent to impersonate legitimate services
- Lack of essential DNS records (MX and TXT records) indicating poor configuration, often associated with phishing
- Domain registration status 'clientHold' raises red flags regarding its legitimacy
Oct 10, 2025
95% confidence
- 11
n***@microsoft-secure.net
View indicators
- Domain impersonation: 'microsoft-secure.net' mimics Microsoft's branding.
- No MX records: The domain is not configured to send or receive emails, unusual for a legitimate domain.
- SPF inclusion: The SPF record indicates a connection to known phishing detection service (KnowBe4), suggesting deception.
Oct 6, 2025
90% confidence
- 12
s***@npmjs.help
View indicators
- Domain has no DNS records indicating it is likely newly registered and potentially malicious.
- Domain using TLD '.help' is uncommon for legitimate organizations, particularly when impersonating 'npmjs'.
- Absence of SSL certificate suggests lack of secure communication.
- Similar domain structure to npmjs.org raises suspicion of impersonation.
Oct 5, 2025
95% confidence
- 13
n***@wa.dol-ug.net
AI analysis failed - using fallback data
View indicators
- Domain impersonation: 'wa.dol-ug.net' mimicking legitimate government domains.
- Urgency manipulation: Email mentions 'urgent payment deadline' and 'suspension of driving privileges' to create panic.
Oct 5, 2025
85% confidence
- 14
r***@gcfhr.net
View indicators
- Newly registered domain: 'gcfhr.net' created on June 26, 2025, raises suspicion.
- Lack of content in the email suggesting potential phishing intent.
- Domain age indicates the possibility of malicious intent due to absence of historical data.
Oct 5, 2025
85% confidence
- 15
n***@gcfhrnet.ct.ws
View indicators
- Lack of MX records suggests no legitimate email configuration for gcfhrnet.ct.ws
- Domain structure ends with '.ws', often associated with dubious activities
- Generic 'noreply' email address indicates possible automatic or unverified system
- Recently registered domain raises red flags for potential phishing
Oct 5, 2025
90% confidence
- 16
i***@oaklandinnsured.com
View indicators
- Domain age: Newly registered domain (August 24, 2025) indicates potential phishing
- Lack of organizational transparency in WHOIS data raises suspicion
- Use of basic SPF record with no evident security behavior
Oct 5, 2025
85% confidence
- 17
i***@oaklandinnsured.com
View indicators
- Domain age: Newly registered domain (August 24, 2025) indicates potential phishing
- Lack of organizational transparency in WHOIS data raises suspicion
- Use of basic SPF record with no evident security behavior
Sep 29, 2025
85% confidence