Notification and current-status evidence
The sent-report ledger records the first outgoing report at .
It contains 11 outgoing records; the latest is dated . The recorded recipient is abuse@domain.me.
The latest stored availability evidence still shows the domain reachable; 6 months has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
lerihex[.]me
Phishing- und Sicherheitsprüfung für lerihex.me
“Lerihex: Most Popular Online Crypto Casino Based on Blockchain”
lerihex.me — Erreichbar · Zugang eingeschränkt (HTTP 403). Markenidentität: Genericcrypto; Betrugstyp: Crypto Scam. Zusammenfassung der Beweislage: VirusTotal 14/93 (ADMINUSLabs, alphaMountain.ai, BitDefender, CyRadar, ESET); URLScan malicious verdict; PhishDestroy score 97/100. Registrar: Key-Systems.
Die ausführliche Analyse von PhishDestroy AI bleibt auf Englisch, damit der ursprüngliche forensische Bericht unverändert bleibt.
Analysis of lerihex.me indicates this domain was actively used for a cryptocurrency-based gambling scam, as evidenced by its page title ('Lerihex: Most Popular Online Crypto Casino Based on Blockchain') and classification as a 'Gambler Scam' phishing kit. The domain was registered on October 6, 2025, through Key-Systems GmbH and resolved to Cloudflare infrastructure (IPv6: 2606:4700:3036::ac43:968e, AS13335) at the time of takedown. Security vendor detections on VirusTotal reached 14 of 93 engines, and the domain appeared on one blocklist (PhishDestroy).
AlienVault OTX recorded one threat intelligence pulse referencing this infrastructure, while Gridinsoft assigned a trust score of 1/100. The site is currently offline, returning an HTTP 403 status, and its SSL certificate was issued by Google Trust Services (WE1). Defenders should note that the domain's Cloudflare nameservers (david.ns.cloudflare.com, zelda.ns.cloudflare.com) and hosting provider are consistent with patterns observed in other crypto-related scams.
While the exact content of the site remains unanalyzed, the combination of low trust scores, vendor detections, and blocklist inclusion confirms malicious intent. Network defenders are advised to block traffic to this domain and monitor for related infrastructure, particularly those using similar Cloudflare configurations or cryptocurrency-themed lures. No legitimate association with blockchain gambling platforms has been identified.
Sicherheitssignale
Pipeline zur Reaktion auf Sicherheitsbedrohungen
Status der öffentlichen Sperrliste
Verlauf der Missbrauchsmeldungen · 11 stored reports over 105 days · click to expand
-
Report #1 Feb 8, 2026 · 18:29 UTCPhishing Abuse Report: lerihex[.]meabuse@key-systems.net
-
Report #2 ICANN CC 148h still active Feb 14, 2026 · 23:04 UTCESCALATION #2 (148h active): Phishing - lerihex[.]meabuse@key-systems.net abuse@domain.me compliance@icann.org
-
Report #3 ICANN CC 582h still active Mar 5, 2026 · 01:22 UTCESCALATION #3 (582h active): Phishing - lerihex[.]meabuse@domain.me compliance@icann.org
-
Report #4 ICANN CC 616h still active Mar 6, 2026 · 11:10 UTCESCALATION #4 (616h active): Phishing - lerihex[.]meabuse@domain.me compliance@icann.org
-
Report #5 ICANN CC 1653h still active Apr 18, 2026 · 18:50 UTCESCALATION #5 (1653h active): Phishing - lerihex[.]meabuse@domain.me compliance@icann.org
-
Report #6 ICANN CC 1697h still active Apr 20, 2026 · 14:59 UTCESCALATION #6 (1697h active): Phishing - lerihex[.]meabuse@domain.me compliance@icann.org
-
Report #7 ICANN CC 1795h still active Apr 24, 2026 · 16:54 UTCESCALATION #7 (1795h active): Phishing - lerihex[.]meabuse@domain.me compliance@icann.org
-
Report #8 ICANN CC 1843h still active Apr 26, 2026 · 17:25 UTCESCALATION #8 (1843h active): Phishing - lerihex[.]meabuse@domain.me compliance@icann.org
-
Report #9 ICANN CC 1893h still active Apr 28, 2026 · 18:30 UTCESCALATION #9 (1893h active): Phishing - lerihex[.]meabuse@domain.me compliance@icann.org
-
Report #10 ICANN CC 2051h still active May 5, 2026 · 08:52 UTCESCALATION #10 (2051h active): Phishing - lerihex[.]meabuse@domain.me compliance@icann.org
-
Report #11 ICANN CC 2504h still active May 24, 2026 · 06:20 UTCESCALATION #11 (2504h active): Phishing - lerihex[.]meabuse@domain.me compliance@icann.org
VirusTotal-Analyse
Archivierte Beweise
Nachweise und externe Berichte
PD-1770575277-lerihex.me Recipient: abuse@domain.me Wurden Sie von dieser Website betroffen?
Wenn Sie Kontoanmeldeinformationen, persönliche oder Zahlungsinformationen eingegeben oder eine Datei von dieser Domain heruntergeladen haben, ergreifen Sie sofort Maßnahmen. Nachfolgend finden Sie Ressourcen, die Ihnen helfen, den Vorfall zu melden und sich zu schützen.
Melden Sie sich bei Ihren örtlichen Behörden
Wählen Sie Ihr Land aus, um Offizielle Kontakte im Bereich Cyberkriminalität oder einen Beschwerdeentwurf erstellen → zu erhalten.
Jede beliebige Domain prüfen
Bedrohungsanalyse anhand gespeicherter Blocklisten, WHOIS, DNS und öffentlicher Scan-Beweise
Jetzt scannenPhishing melden
Melden Sie verdächtige Domains an unsere Bedrohungsdatenbank – schützen Sie die Community
MeldenEchtzeit-Bedrohungsfeed
Aktuelle Phishing-Meldungen und beobachtete Verfügbarkeitsänderungen
ÜberwachenBleiben Sie auf dem Laufenden, bleiben Sie sicher
Beobachten Sie aktuelle Bedrohungen oder legen Sie Widerspruch gegen diesen Eintrag ein, wenn Sie der Meinung sind, dass es sich um einen Fehlalarm handelt