Notification and current-status evidence
The sent-report ledger records the first outgoing report at .
The recorded recipient is wegsdg2@eszmc.com.
The latest stored availability evidence still shows the domain reachable; 13 days has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
click-2026fifalottery[.]com[.]cn
“2026世界杯(FIFA WorldCUP)中国体育彩票指定平台”
Analysis conducted on August 03, 2026, identifies click-2026fifalottery.com.cn as an active phishing domain targeting users with a FIFA lottery-themed scam. The domain is currently flagged by one security blocklist, specifically PhishDestroy, indicating elevated risk. VirusTotal data reveals that one of ninety-one security vendors has detected the domain as malicious, though the limited detection count suggests the campaign may still be in an early or evasive phase.
No additional details regarding hosting infrastructure, autonomous system number, or registrar are provided in available intelligence, limiting further attribution. The domain name incorporates '2026fifalottery,' strongly suggesting an attempt to exploit interest in the 2026 FIFA World Cup, though no confirmed brand impersonation or official affiliation has been verified. The exact content of the site remains unanalyzed; as such, specific phishing mechanisms, such as credential harvesting forms or fraudulent payment requests, cannot be confirmed.
Defenders are advised to treat this domain as a potential threat vector, particularly in environments where FIFA-related promotions or communications are expected. Network-level blocking is recommended based on existing blocklist inclusion, and users should be cautioned against interacting with any communications or links associated with this domain. Further monitoring of detection trends and infrastructure pivots is warranted to assess the campaign's evolution.
Threat Response Pipeline
Public Blocklist Status
Casino / Gambling License Verification
Technologies · 3 identified
Nginx is a web server that can also be used as a reverse proxy, load balancer, mail proxy and HTTP cache.
nginx.org 100% confidenceHTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org 100% confidenceBaidu Analytics (百度统计) is a free tool for tracking and reporting traffic data of users visiting your site.
tongji.baidu.com 100% confidenceVirusTotal Analysis
Archived Evidence
Site Performance Analysis
Google PageSpeed Insights — mobile performance audit of click-2026fifalottery.com.cn · checked Aug 4, 2026
Site Configuration Analysis
Evidence & External Reports
PD-20260804-244D2D Recipient: wegsdg2@eszmc.com Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive