Skip to security report
⚠️
This domain has been flagged as malicious
Security engines reporting a detection: 4. Exercise extreme caution — do not enter credentials or personal information.
Domain security and threat intelligence

discordseason[.]pro

“GO VERIFY YOURSELF”

Threat verdict Critical 86/100 evidence score
Availability Cloaked · reachable Reachability observed through cloaking checks
VirusTotal detections: 4/91 URLQuery threat systems: 1 alert Brand impersonation: Discord Last known active
Apr 23, 2026 Discord 1 Report Sent

Stored detection

Cloaking alert

Cloaking type
content_divergence
Cloaking score
2/6

Evidence Summary

CRITICAL
Evidence score
86/100

PhishDestroy identifies discordseason.pro as an active phishing site impersonating Discord’s identity verification page. The domain presents a fraudulent login interface designed to harvest user credentials while deploying a cryptocurrency drainer payload upon connection. Prompt action is critical as the page title ‘GO VERIFY YOURSELF’ mirrors legitimate Discord messaging, creating a high-fidelity deception for unsuspecting users seeking account recovery or 2FA setup. This domain was flagged with an elevated risk level and is currently unresolved by 94 out of 95 VirusTotal security vendors despite clear malicious intent. It resolves to IP 5.253.61.77 via Let’s Encrypt SSL issued on April 20, 2026, and is registered through NICENIC INTERNATIONAL GROUP CO., LIMITED—an anonymization-friendly registrar with a history of enabling malicious domains. The combination of a recent creation date, low detection coverage, and IP reputation raises the likelihood of ongoing exploitation targeting Discord users and communities. To mitigate exposure, users should avoid accessing discordseason.pro and inspect any links claiming to originate from Discord for mismatches in domain spelling or HTTPS validity. If credentials were entered, rotate passwords immediately and revoke unauthorized device access in account settings. Report the domain to PhishDestroy and monitor wallet activity for signs of crypto drainer activity. Block the IP 5.253.61.77 at the network level where possible to prevent further access by the threat actor behind this campaign.

Submitted Evidence Snapshot

Sent
Ledger records
1
Case ID
PD-20260423-E4EC6D
Captured page title
GO VERIFY YOURSELF
PDF artifact
PDF evidence
Full evidence text
Registrar: NICENIC International Group Co., Limited (Hong Kong (China))
Policy Violations: “Services may be used only for lawful purposes… fraud, abuse and illegal activity prohibited. Violations may result in immediate suspension.” + dedicated abuse handling and takedown
Applicable Laws: Crimes Ordinance Cap.200 (Fraud), Theft Ordinance Cap.210 §16A (fraud by deception), Personal Data (Privacy) Ordinance Cap.486
VirusTotal
VirusTotal
4 det.
URLQuery
URLQuery
1 threat alert
DNS Security
1/12
TLS Certificate
Let's Encrypt
Age
4 mo
Observed status
Cloaked · reachable
PhishDestroy
DestroyList
Listed
Reports Sent
1

Data Coverage

VirusTotal 4 / 91 URLQuery 1 threat-system alert PhishStats checked — no match recorded OTX no community references CF Radar scan completed URLScan capture stored report URLScan verdict Analysis completed DNS blocks 1/12 TLS valid certificate, 87d WHOIS 4 mo old Screenshot 3 captures · 3 sources Redirect chain not probed
Network Security IntelligenceRegistrar context
DNS Provider Blocks 1 / 12
Brand Discord
Threat Detection Systems 1 alert
Detection System Indicator Verdict Alert
DNS4EU discordseason.pro malicious Sinkholed
Registrar context NiceNIC
Stored registration data identifies NICENIC INTERNATIONAL GROUP CO., LIMITED (IANA 3765) as the registrar. PhishDestroy maintains separate NiceNIC abuse-report research; registrar association is contextual and is not an independent detection for this domain.
NiceNIC Verdict Full Investigation

Threat Response Pipeline

Discovery
Checks
Reports
Availability
13/14

Blocklist coverage

10 monitored external feeds · stored snapshot Aug 12, 2026

10 monitored external feeds No match

Stored outcome evidence

Outcome & takedown attribution

Outcome
held
Availability
unreachable
Cause
registrar_client_hold
Actor
NICENIC INTERNATIONAL GROUP CO., LIMITED
Mechanism
client_hold
Confidence
95%
First observation
Latest observation

Estimated unavailability

Time to unavailability: 0 h

Evidence SHA-256 f3355dc3e984

Detection timeline

  1. Availability

    First stored value: DNS inactive

    f93a11f87e4d
  2. Availability

    DNS inactive → Unknown

    c064216d1962
  3. Domain status

    Reachable → Unreachable

  4. Availability

    Unknown → DNS inactive

    a6a4cfb44227
  5. Availability

    DNS inactive → Unknown

    a0aa7736b627
  6. Availability

    Unknown → Held

    f52f7c20dbc9
  7. Availability

    Held → Unknown

    1a1aa8e19724
  8. Availability

    Unknown → DNS inactive

    6dfe9145995c
  9. Availability

    DNS inactive → Held

    33c7543e126a
  10. Availability

    Held → DNS inactive

    641ed81dc4d5
Show all (11)
  1. Availability

    DNS inactive → Unknown

    c0996c1e448b
  2. Availability

    Unknown → Held

    1455b4e4a4b1
  3. Availability

    Held → Unknown

    c483ed778bbd
  4. Availability

    Unknown → DNS inactive

    d0b7046e8c2f
  5. Availability

    DNS inactive → Held

    9fb1272e2d88
  6. Availability

    Held → DNS inactive

    ca9ed662b468
  7. Availability

    DNS inactive → Unknown

    66c4ba2d04da
  8. Availability

    Unknown → Held

    8397e02984ed
  9. Availability

    Held → DNS inactive

    92f667ff6e00
  10. Availability

    DNS inactive → Unknown

    8ac0ec09fedc
  11. Availability

    Unknown → Held

    f3355dc3e984

Community reports

Reported by 1 community member, first seen Apr 23, 2026

Stored reports
1
Unique reported URLs
1
Accepted1

Stored Capture

Page Title
GO VERIFY YOURSELF
TLS Certificate
Valid transport encryption · Issued by Let's Encrypt · valid for 87 days

Domain Intelligence

Domain
URLScan Verdict Analysis completed score 0 report ↗
Server / ASN nginx · AS211642 AdminVPS OOO
IP Reputation IP abuse confidence 0/100 0 reports checked Jul 13, 2026
IP Address 5.253.61.77 RU
GeoRU Moscow, RU
NetworkAS211642 · Adminvps
RegistrationCreated Apr 20, 2026 (114d) Expires Apr 20, 2027
Elapsed Since First Report 77 days
What we count Raw elapsed time since the first stored abuse report. It is not a registrar response-time measurement. Latest observed status: Cloaked · reachable.
What each report contains Stored outgoing-report records may reference evidence available at the time, such as vendor verdicts, registration data, hosting details, classifications, or screenshots. This page does not infer the exact payload delivered, receipt, acknowledgement, or action by a recipient.
Technical detailsDNS, TLS names and timestamps
First DetectedApr 23, 2026
Submitted URLhttps://discordseason.pro/
Nameserversns1.adminvps.runs2.adminvps.netns3.adminvps.runs4.adminvps.net
MX Records10 mail.discordseason.pro 20 mail.discordseason.pro
TLS observationscanned Jul 9, 2026
ICANN OVERSIGHT

Accreditation and RAA context

Registrar accreditation and DNS abuse obligations

For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.

Accreditation is a contract, not a safety certification.

RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.

Accountability draft Nothing is sent automatically.

Technologies

3 high-confidence technologies identified

Nginx jQuery UI jQuery
Cloudflare Radar
Report This Domain Submit evidence & help protect others

VirusTotal Analysis

4 / 91 security vendors flagged this domain
View on VT
Last analyzed
alphaMountain.ai
Forcepoint ThreatSeeker
Gridinsoft
SOCRadar
Site Performance Analysis

Google PageSpeed Insights — mobile performance audit of discordseason.pro · checked Apr 23, 2026

65
Needs Work
Performance
FCP
3.65s
First Contentful Paint
LCP
9.35s
Largest Contentful Paint
CLS
0
Cumulative Layout Shift
TBT
0ms
Total Blocking Time
SI
4.77s
Speed Index
Powered by Google PageSpeed Insights · Mobile strategy · Scores: 90-100 Good 50-89 Needs Work 0-49 Poor

Were You Affected by This Site?

If credentials were compromised, report immediately. Do not engage with recovery scammers.

If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.

Europol
Find the official reporting channel for your EU country
National police directory
Beware of recovery scammers! Recovery scammers may pose as investigators, lawyers, or tracing services. Do not pay upfront fees or disclose credentials. Learn more about recovery fraud →

Report to Your Local Authorities

Select your country to get official cybercrime contacts, or create a complaint draft →.

97-country directory
Template-based draft • optional AI wording assistance requires separate consent Review and submit it yourself

Check Any Domain

Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence

Scan Now

Report Phishing

Submit suspicious domains to our threat database — protect the community

Report

Live Threat Feed

Recent phishing reports and observed availability changes

Monitor

Stay Informed, Stay Safe

Monitor live threats or contest this listing if you believe it's a false positive

Live Threat Feed Appeal This Listing

External tools

HTML · IFRAME

Embed This Report

Share this threat intelligence on your website or blog

embed.html
<iframe
  src="https://phishdestroy.io/embed/domain/discordseason.pro"
  title="PhishDestroy threat report for discordseason.pro"
  width="100%" height="320"
  loading="lazy"
  referrerpolicy="no-referrer"
  sandbox="allow-same-origin allow-popups allow-popups-to-escape-sandbox"
  style="border:0;border-radius:12px;max-width:100%"
></iframe>

A Very Sincere Thank-You Note

Satirical draft generator

Recipient
Fee context

Satirical draft. Fee figures are estimates; exact attribution to this domain is not claimed.