discordseason[.]pro
“GO VERIFY YOURSELF”
Stored detection
Cloaking alert
- Cloaking type
content_divergence- Cloaking score
- 2/6
Evidence Summary
PhishDestroy identifies discordseason.pro as an active phishing site impersonating Discord’s identity verification page. The domain presents a fraudulent login interface designed to harvest user credentials while deploying a cryptocurrency drainer payload upon connection. Prompt action is critical as the page title ‘GO VERIFY YOURSELF’ mirrors legitimate Discord messaging, creating a high-fidelity deception for unsuspecting users seeking account recovery or 2FA setup. This domain was flagged with an elevated risk level and is currently unresolved by 94 out of 95 VirusTotal security vendors despite clear malicious intent. It resolves to IP 5.253.61.77 via Let’s Encrypt SSL issued on April 20, 2026, and is registered through NICENIC INTERNATIONAL GROUP CO., LIMITED—an anonymization-friendly registrar with a history of enabling malicious domains. The combination of a recent creation date, low detection coverage, and IP reputation raises the likelihood of ongoing exploitation targeting Discord users and communities. To mitigate exposure, users should avoid accessing discordseason.pro and inspect any links claiming to originate from Discord for mismatches in domain spelling or HTTPS validity. If credentials were entered, rotate passwords immediately and revoke unauthorized device access in account settings. Report the domain to PhishDestroy and monitor wallet activity for signs of crypto drainer activity. Block the IP 5.253.61.77 at the network level where possible to prevent further access by the threat actor behind this campaign.
Submitted Evidence Snapshot
- Sent
- Ledger records
- 1
- Case ID
PD-20260423-E4EC6D- Captured page title
- GO VERIFY YOURSELF
- PDF artifact
- PDF evidence
Full evidence text
Policy Violations: “Services may be used only for lawful purposes… fraud, abuse and illegal activity prohibited. Violations may result in immediate suspension.” + dedicated abuse handling and takedown
Applicable Laws: Crimes Ordinance Cap.200 (Fraud), Theft Ordinance Cap.210 §16A (fraud by deception), Personal Data (Privacy) Ordinance Cap.486
Data Coverage
Network Security Intelligence
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DNS4EU | discordseason.pro |
malicious | Sinkholed |
Threat Response Pipeline
Blocklist coverage
10 monitored external feeds · stored snapshot Aug 12, 2026
10 monitored external feeds No match
Stored outcome evidence
Outcome & takedown attribution
- Outcome
held- Availability
unreachable- Cause
registrar_client_hold- Actor
- NICENIC INTERNATIONAL GROUP CO., LIMITED
- Mechanism
client_hold- Confidence
- 95%
- First observation
- Latest observation
Estimated unavailability
Time to unavailability: 0 hEvidence SHA-256 f3355dc3e984
Detection timeline
-
Availability
First stored value: DNS inactive
f93a11f87e4d -
Availability
DNS inactive → Unknown
c064216d1962 -
Domain status
Reachable → Unreachable
-
Availability
Unknown → DNS inactive
a6a4cfb44227 -
Availability
DNS inactive → Unknown
a0aa7736b627 -
Availability
Unknown → Held
f52f7c20dbc9 -
Availability
Held → Unknown
1a1aa8e19724 -
Availability
Unknown → DNS inactive
6dfe9145995c -
Availability
DNS inactive → Held
33c7543e126a -
Availability
Held → DNS inactive
641ed81dc4d5
Show all (11)
-
Availability
DNS inactive → Unknown
c0996c1e448b -
Availability
Unknown → Held
1455b4e4a4b1 -
Availability
Held → Unknown
c483ed778bbd -
Availability
Unknown → DNS inactive
d0b7046e8c2f -
Availability
DNS inactive → Held
9fb1272e2d88 -
Availability
Held → DNS inactive
ca9ed662b468 -
Availability
DNS inactive → Unknown
66c4ba2d04da -
Availability
Unknown → Held
8397e02984ed -
Availability
Held → DNS inactive
92f667ff6e00 -
Availability
DNS inactive → Unknown
8ac0ec09fedc -
Availability
Unknown → Held
f3355dc3e984
Community reports
Reported by 1 community member, first seen Apr 23, 2026
- Stored reports
- 1
- Unique reported URLs
- 1
Stored Capture
Domain Intelligence
Technical detailsDNS, TLS names and timestamps
ICANN OVERSIGHT
Accreditation and RAA context
Accreditation and RAA context
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Technologies
3 high-confidence technologies identified
VirusTotal Analysis
Site Performance Analysis
Google PageSpeed Insights — mobile performance audit of discordseason.pro · checked Apr 23, 2026
Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive