Notification and current-status evidence
The sent-report ledger records the first outgoing report at .
The recorded recipient is abuse@dynadot.com.
The latest stored availability evidence still shows the domain reachable; 4 months has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
portal-zestprotocol[.]xyz
“portal-zestprotocol.xyz | 504: Gateway time-out”
portal-zestprotocol.xyz — لم يتم التحقق منها. نوع الاحتيال: Fake Exchange. ملخص الأدلة: VirusTotal 5/91 (alphaMountain.ai, Chong Lua Dao, Forcepoint ThreatSeeker, Gridinsoft, SOCRadar); URLQuery 1 alert; 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 69/100. مسجّل النطاق: Dynadot.
يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.
Portal-zestprotocol.xyz has been flagged by PhishDestroy as an active brand spoofing phishing domain designed to impersonate a legitimate financial protocol portal. This threat specifically targets unsuspecting users by mimicking well-known finance platforms to steal login credentials and sensitive financial information. The domain was registered only days ago, on March 25, 2026, which indicates a highly opportunistic and potentially short-lived campaign aimed at capitalizing on recent trends or hype around decentralized finance protocols. Users accessing this site risk immediate credential theft or malware exposure through deceptive login interfaces disguised as legitimate portals. PhishDestroy identifies this domain presents active brand spoofing risks with minimal detection coverage at present. VirusTotal currently shows 4 out of 95 security engines flagging the domain. The site was registered through Dynadot LLC and resolved to IP address 172.67.143.178. It operates under a valid Let's Encrypt SSL certificate, which may give false reassurance of legitimacy. Despite no blocklist entries detected yet, the domain’s recent creation date and low detection rate suggest it is either newly deployed or flying under the radar. The absence of historical trust data and the use of a content delivery network IP (Cloudflare AS13335) increases opacity around hosting infrastructure and ownership. These technical indicators—particularly the fresh registration, uncommon domain syntax, and valid-but-abused SSL certificate—are consistent with active phishing infrastructure designed for credential harvesting. In response to this brand spoofing threat, users should immediately cease all interaction with portal-zestprotocol.xyz and avoid entering any credentials or personal information. Organizations are advised to block both the domain and its underlying IP address (172.67.143.178) at network and DNS levels. Shared threat intelligence should be updated with the unique seed identifier 0359c6 to prevent cross-contamination. Security teams must monitor for lateral movement if credentials were previously entered, as stolen login data may be used in follow-up attacks. This domain exemplifies how attackers leverage legitimate-looking domains and valid SSL certificates to bypass security controls and deceive users, reinforcing the need for layered defenses including user awareness training, real-time phishing detection, and proactive domain monitoring. Due to the evolving nature of this threat and low initial detection rates, continuous monitoring and rapid response are critical.
استخبارات أمن الشبكات
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DNS4EU | llama-rpc-mainnet.com |
malicious | Sinkholed |
مسار الاستجابة للتهديدات Pipeline
حالة قوائم الحظر العامة
لقطة محفوظة
معلومات النطاق
التفاصيل الفنيةDNS، أسماء المجال البديلة (SAN) في بروتوكول SSL، الطوابع الزمنية
ICANN OVERSIGHT
الاعتماد وسياق RAA
الاعتماد وسياق RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
التقنيات · 2 identified
Web infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
تحليل VirusTotal
الأدلة والتقارير الخارجية
PD-20260326-569B22 Recipient: abuse@dynadot.com هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب