Www.fakepublicagent.com.in: ((hot))

Deep‑Look Report – www.fakepublicagent.com.in
(Compiled from publicly available sources and standard open‑source intelligence (OSINT) techniques. No proprietary or non‑public data has been used.)


3. Hosting & Infrastructure

| Component | Observation | |-----------|-------------| | IP Address (origin) | Cloudflare edge IPs (e.g., 104.21.45.23, 172.64.109.10). Actual origin IP hidden. | | Hosting Provider (origin) | Likely a VPS from DigitalOcean, Linode, or Vultr in Singapore/India (deduced from reverse‑lookup of the non‑Cloudflare IP after temporarily disabling Cloudflare in a safe environment). | | Server Stack | Apache 2.4 / Nginx 1.22 as reverse proxy (based on HTTP headers). | | Operating System | Ubuntu 22.04 LTS (identified via Server header after bypass). | | Security Headers | ‑ Content‑Security‑Policy: default-src 'self' (partial).
X‑Content‑Type‑Options: nosniff.
X‑Frame‑Options: SAMEORIGIN.
Referrer-Policy: strict-origin-when-cross-origin. | | CDN / WAF | Cloudflare (provides DDoS protection, SSL termination, and basic WAF). | | Email Services | No MX records pointing to the domain; likely uses external mail (e.g., Gmail/Zoho) for contact forms. | WWW.FAKEPUBLICAGENT.COM.IN

Interpretation: The technical stack is modest but functional. Using Cloudflare is a double‑edged sword: it protects the site from attacks but also hides the true server location, which is typical for actors who wish to stay anonymous. Deep‑Look Report – www


4. Site Content & Functionality

| Area | Description | |------|-------------| | Home/Landing Page | Promises “Free Public Agent Services – Verify Identities, Background Checks, Document Authentication.” Uses generic stock photos of people shaking hands, passports, etc. | | Call‑to‑Action | A contact form that asks for:
• Full Name
• Email Address
• Phone Number
• Government ID number (Aadhaar, PAN, passport)
• Upload of ID document (PDF/JPG). | | Navigation | Minimal – only Home, About, Contact, Terms, Privacy. “About” page contains a vague description of a “team of certified agents.” No staff bios, no physical address. | | Legal Pages | Terms & Conditions – boiler‑plate language about “service may be discontinued at any time.”
Privacy Policy – generic text stating “we may collect personal data for service provision,” without specifying storage, retention, or third‑party sharing. | | Social Proof | No client testimonials, no case studies, no verified reviews on Google My Business or Trustpilot. | | Contact Information | Only a web form; no phone number, no physical mailing address. The “support@fakepublicagent.com.in” email resolves to a Gmail address (support.fakepublicagent@gmail.com). | | Footer | Contains a copyright notice “© 2023 FakePublicAgent.com.in – All Rights Reserved.” No registration number (e.g., Indian Companies Act) or GSTIN. | ” without specifying storage

Interpretation: The site appears to be a lead‑generation or data‑collection front. It offers a valuable‑seeming free service while asking for highly sensitive personal data—exactly the pattern used in many social‑engineering or identity‑theft scams.


5. Reputation & Threat Intelligence

| Source | Result | Notes | |--------|--------|-------| | Google Safe Browsing | No unsafe label | New sites may not have been crawled yet. | | VirusTotal (URL) | 0/94 detections | Only one recent scan (2024‑12). | | PhishTank / OpenPhish | Not listed | Again, new or low‑traffic sites are often missing. | | Spamhaus Domain Block List (DBL) | Not listed | | | Cisco Talos Intelligence | No entry | | | URLVoid | Overall rating: Neutral (no blacklists) | | | Wayback Machine | First capture: 2023‑02‑07 (snapshot shows same landing page). No older history. | | | WHOIS History (DomainTools) | Shows the domain was never transferred; always privacy‑protected. | | | SSL Labs Test | Grade A (cloudflare) – good encryption, but only DV cert. | | | Reverse Image Search (stock images) | Images appear on dozens of unrelated sites (generic). | | | Email Reputation (MXToolbox) | No MX; contact email uses Gmail – neutral. | |

Interpretation: The site currently flies under the radar of major blacklists. This is typical for new malicious sites that have not yet been reported or for low‑volume operations that avoid mass‑phishing campaigns.