Threat catalog

Search saved risk checks

Find domains and senders already saved from a risk check. Each result has a public page Google can index.

Inventory

17

Results

17 matches

  1. 01

    sfrclak.com

    CRITICALVerified

    i***@sfrclak.com

    View indicators
    • Malicious Packages: axios@1.14.1, axios@0.30.4, plain-crypto-js@4.2.1
    • C2 Server: sfrclak.com (IP: 142.11.206.73)
    • File Indicators: macOS File /Library/Caches/com.apple.act.mond; Windows File %PROGRAMDATA%\wt.exe; Linux File /tmp/ld.py

    Open public report

    Mar 31, 2026

    95% confidence

  2. 02

    wa.org-etcxh.bond

    CRITICALVerified

    i***@wa.org-etcxh.bond

    View indicators
    • Suspicious domain: 'wa.org-etcxh.bond' suggesting potential phishing intent
    • Domain structure: complex with 'etcxh.bond', typical of malicious domains
    • Missing DNS records: lack of MX and TXT records indicating fraudulent configuration
    • Domain impersonation: attempting to mimic Washington DMV through altered domain

    Open public report

    Feb 28, 2026

    90% confidence

  3. 03

    events.1haoxi.com

    HIGHVerified

    p***@events.1haoxi.com

    View indicators
    • Domain age: Newly registered domain 'events.1haoxi.com' with no DNS records raises suspicion.
    • Lack of DNS records: No A, MX, TXT, NS, or CNAME records found for 'events.1haoxi.com', indicating a potentially fraudulent domain.
    • Unsolicited job offer: Generic and vague email content claiming to offer high compensation for part-time work is a common phishing tactic.
    • Urgency manipulation: Requesting immediate action by asking recipients to text 'More Info' to an unknown number is a classic scam approach.

    Open public report

    Jan 13, 2026

    90% confidence

  4. 04

    h.lushanotice.com

    HIGHVerified

    l***@h.lushanotice.com

    View indicators
    • Unusual domain structure: subdomain 'h.lushanotice.com' lacks credibility.
    • Weak anti-spoofing policies: SPF record includes 'mailgun.org' but lacks strict enforcement ('~all').
    • Absence of DMARC policy enforcement: DMARC set to 'p=none', indicating vulnerability.
    • Lack of SSL certificate raises concerns about legitimacy.
    • Content title: 'Personal Information Notice' commonly associated with phishing tactics.

    Open public report

    Jan 6, 2026

    85% confidence

  5. 05

    wa.gov-vja.bond

    HIGHVerified

    i***@wa.gov-vja.bond

    View indicators
    • impersonation: The sender uses '[sender display name]' instead of '[sender name]'
    • urgency: The message explicitly states '[time pressure language found]'
    • suspicious_url: The URL 'https://wa.gov-vja.bond/dol?var=CBiacvjacx' is visible
    • domain impersonation: 'wa.gov-vja.bond' mimicking legitimate government domains
    • lack of MX records indicates potential phishing
    • uncommon TLD '.bond' raises suspicion

    Open public report

    Dec 11, 2025

    85% confidence

  6. 06

    n***@e-zpassny.hsmv-ay.work

    View indicators
    • Impersonation: Email from sender 'noreply@e-zpassny.hsmv-ay.work' mimics legitimate service branding.
    • Urgency manipulation: Message demands immediate payment 'before enforcement occurs' to incite fear.
    • Suspicious URL: Links to 'https://e-zpassny.hsmv-ay.work/' which uses a generic domain.
    • Generic display name: Sender details lack specific branding, indicating possible phishing.

    Open public report

    Oct 15, 2025

    90% confidence

  7. 07

    i***@e-zpassny.adgpay.cc

    View indicators
    • Urgency: 'Suspension effective October 16th'
    • Suspicious URL: 'https://e-zpassny.adgpay.cc/us'
    • Domain impersonation: 'e-zpassny.adgpay.cc' masquerading as EZPass
    • Social engineering: 'Go to a toll booth and be charged a 35% service fee'

    Open public report

    Oct 15, 2025

    95% confidence

  8. 08

    uncsds-summit.org

    HIGHVerified

    p***@uncsds-summit.org

    View indicators
    • Domain age: Newly registered domain (August 4, 2025) indicates potential phishing
    • SPF record includes third-party domains (mailbaby.net), suggesting email forgery

    Open public report

    Oct 12, 2025

    85% confidence

  9. 09

    szjuanbai.xyz

    HIGHVerified

    n***@szjuanbai.xyz

    View indicators
    • Domain age: Newly registered domain (September 4, 2023) indicates potential phishing
    • Lack of A records for 'szjuanbai.xyz' suggests suspicious intent
    • Absence of standard DNS records (TXT, CNAME)
    • Domain registration with Gname.com, known for spam or phishing associations

    Open public report

    Oct 12, 2025

    85% confidence

  10. 10

    rnicrosoft.com

    CRITICALVerified

    n***@rnicrosoft.com

    View indicators
    • Domain impersonation: 'rnicrosoft.com' closely resembles 'microsoft.com'
    • Known malicious patterns: The use of 'noreply' in the email address suggests an intent to impersonate legitimate services
    • Lack of essential DNS records (MX and TXT records) indicating poor configuration, often associated with phishing
    • Domain registration status 'clientHold' raises red flags regarding its legitimacy

    Open public report

    Oct 10, 2025

    95% confidence

  11. 11

    n***@microsoft-secure.net

    View indicators
    • Domain impersonation: 'microsoft-secure.net' mimics Microsoft's branding.
    • No MX records: The domain is not configured to send or receive emails, unusual for a legitimate domain.
    • SPF inclusion: The SPF record indicates a connection to known phishing detection service (KnowBe4), suggesting deception.

    Open public report

    Oct 6, 2025

    90% confidence

  12. 12

    npmjs.help

    HIGHVerified

    s***@npmjs.help

    View indicators
    • Domain has no DNS records indicating it is likely newly registered and potentially malicious.
    • Domain using TLD '.help' is uncommon for legitimate organizations, particularly when impersonating 'npmjs'.
    • Absence of SSL certificate suggests lack of secure communication.
    • Similar domain structure to npmjs.org raises suspicion of impersonation.

    Open public report

    Oct 5, 2025

    95% confidence

  13. 13

    wa.dol-ug.net

    HIGHVerified

    n***@wa.dol-ug.net

    AI analysis failed - using fallback data

    View indicators
    • Domain impersonation: 'wa.dol-ug.net' mimicking legitimate government domains.
    • Urgency manipulation: Email mentions 'urgent payment deadline' and 'suspension of driving privileges' to create panic.

    Open public report

    Oct 5, 2025

    85% confidence

  14. 14

    gcfhr.net

    HIGHVerified

    r***@gcfhr.net

    View indicators
    • Newly registered domain: 'gcfhr.net' created on June 26, 2025, raises suspicion.
    • Lack of content in the email suggesting potential phishing intent.
    • Domain age indicates the possibility of malicious intent due to absence of historical data.

    Open public report

    Oct 5, 2025

    85% confidence

  15. 15

    gcfhrnet.ct.ws

    HIGHVerified

    n***@gcfhrnet.ct.ws

    View indicators
    • Lack of MX records suggests no legitimate email configuration for gcfhrnet.ct.ws
    • Domain structure ends with '.ws', often associated with dubious activities
    • Generic 'noreply' email address indicates possible automatic or unverified system
    • Recently registered domain raises red flags for potential phishing

    Open public report

    Oct 5, 2025

    90% confidence

  16. 16

    i***@oaklandinnsured.com

    View indicators
    • Domain age: Newly registered domain (August 24, 2025) indicates potential phishing
    • Lack of organizational transparency in WHOIS data raises suspicion
    • Use of basic SPF record with no evident security behavior

    Open public report

    Oct 5, 2025

    85% confidence

  17. 17

    i***@oaklandinnsured.com

    View indicators
    • Domain age: Newly registered domain (August 24, 2025) indicates potential phishing
    • Lack of organizational transparency in WHOIS data raises suspicion
    • Use of basic SPF record with no evident security behavior

    Open public report

    Sep 29, 2025

    85% confidence