Live threat picture

Scam Radar

What's circulating right now, from public threat data: fresh malicious-URL activity and look-alike domains of brands scammers love to impersonate. Refreshed several times a day.

Updated about 3 hours ago

Malicious URLs

Fresh malicious-URL activity

100 malicious URLs in the latest public feed batch — 63 still online right now.

Mozi elf 32-bit mips mirai

Recently affected hosts (defanged — do not visit):

  • gaiadeqi[.]com
  • seobandung[.]site
  • wind[.]ntlsmartfull[.]com
  • lively-fog-af49[.]pablosoftwareplus[.]workers[.]dev
  • res[.]cloudinary[.]com
  • pub-0216fa08b2b94e129cb9e002cf7cb1f4[.]r2[.]dev

Source: URLhaus by abuse.ch (researcher-curated public feed)

Look-alike domains

Look-alike sweep: frequently impersonated brands

We generate the most common typo and look-alike spellings of these brands' real domains and check which ones actually exist in DNS today.

Brand Live look-alikes Registered (dormant) Examples (defanged)
Interac
interac.ca
9 3 intera[.]ca intrac[.]ca nterac[.]ca interac[.]co
Government of Canada
canada.ca
22 2 anada[.]ca c4nada[.]ca ca-nada[.]ca caada[.]ca
Canada Post
canadapost-postescanada.ca
4 0 canadapost-postecanada[.]ca canadapostpostescanada[.]ca canadapost-postescanada[.]com canadapost-postescanada[.]org
Desjardins
desjardins.com
23 1 dejsardins[.]com desajrdins[.]com desardins[.]com desjadins[.]com
RBC
rbc.com
23 2 bc[.]com brc[.]com dbc[.]com ebc[.]com
BMO
bmo.com
27 3 8mo[.]com b-mo[.]com bbmo[.]com bjo[.]com
Amazon
amazon.ca
22 7 aamazon[.]ca aamzon[.]ca aazon[.]ca amaazon[.]ca
Netflix
netflix.com
33 2 account-netflix[.]com entflix[.]com etflix[.]com n3tflix[.]com

A registered look-alike is not automatically malicious — companies defensively register many of their own typos. The point is awareness: these spellings exist, so read domains carefully.

Why the dots are in brackets

Host names on this page are deliberately broken with [.] so they can't be clicked or auto-linked. Don't reassemble and visit them.

Scam of the Week

The fake Desjardins security-alert call — A text flags a suspicious transaction on your Desjardins account and invites you to reply. The call that follows is a fake security agent after the code that was just texted to you - or after a transfer to a "secure account."