Notification and current-status evidence
The sent-report ledger records the first outgoing report at . A report was sent to the recorded registrar; contact details remain in Domain Intelligence. The latest stored availability evidence still shows the domain reachable; 5 months has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
drainerluna[.]ru
“Thank You Drainerluna & AMLSec for Finance Innovations”
اكتشاف محفوظ
تنبيه إخفاء المحتوى
- نوع الإخفاء
content_divergence- درجة الإخفاء
- 2/6
ملخص الأدلة
drainerluna.ru was registered on 21 February 2026 through the .ru TLD registry. The domain resolves to 172.67.206.199, an address owned by AS13335 Cloudflare, Inc., and is served from Cloudflare edge nodes using HTTP/3 and Cloudflare Browser Insights. The SSL certificate is issued by Google Trust Services under the WE1 profile, and the site returns HTTP 200. The page title observed is “Thank You Drainerluna & AMLSec for Finance Innovations”, which does not reference the targeted brand but the domain is flagged as impersonating Avalanche in a crypto‑drain scam context.
Gridinsoft assigns a trust score of 0/100, indicating a high likelihood of malicious intent. Four of ninety‑one VirusTotal scanners reported the domain as malicious, and the domain is listed on a single security blocklist and has been blocked by PhishDestroy. The infrastructure uses the nameservers izabella.ns.cloudflare.com and elias.ns.cloudflare.com, confirming reliance on Cloudflare’s DNS service. The combination of a recent registration date, low trust score, partial detection by antivirus engines, and active blocklist listings suggests an ongoing campaign targeting users of the Avalanche platform.
Uncertainty remains regarding the exact phishing page content, as no visual analysis is available; only the page title and metadata have been captured. Defenders should add the domain to network and DNS block policies, monitor for additional domains using the same nameservers or Cloudflare IP ranges, and consider sharing indicators of compromise with threat‑intel platforms. Continuous re‑scanning is advised to capture any changes in detection status.
لقطة الأدلة المرسلة
- أُرسل
- سجلات الدفتر
- 1
- معرّف القضية
PD-1771138053-drainerluna.ru- ملف PDF
- دليل PDF
سجل البلاغات 1
- البلاغ 1 Phishing Abuse Report: drainerluna[.]ru
Data Coverage
مسار الاستجابة للتهديدات Pipeline
تغطية قوائم الحظر
١٠ مصادر خارجية مراقبة · لقطة محفوظة 13/08/2026
المخطط الزمني للاكتشاف
-
حالة النطاق
يمكن الوصول إليه ← يتعذر الوصول إليه
-
Cloudflare Radar
تم حفظ فحص Cloudflare Radar · فتح الفحص
تحليل VirusTotal
هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب