gold-idn[.]com
“GOLDEN DOMAIN”
Evidence Summary
Analysis of www.gold-idn.com indicates that the domain was created on 23 February 2026 and is currently hosted on Cloudflare’s network (ASN 13335, United States). The authoritative nameservers are armfazh.ns.cloudflare.com and carla.ns.cloudflare.com, and the domain resolves to IP address 172.67.171.28. The site presented a page title of "GOLDEN DOMAIN" but no SSL certificate was observed, implying an HTTP‑only service at the time of capture.
Registration was performed through Dominet (HK) Limited, a registrar based in Hong Kong. The domain has been taken offline and is listed as blocked by the PhishDestroy mitigation service, and it appears on one external security blocklist. VirusTotal records show that the domain was scanned by 93 AV engines without any detections, but the absence of detections does not constitute a safety guarantee.
No additional intelligence such as Safe Browsing, OTX, or brand‑specific targeting was supplied, leaving the precise phishing campaign context unknown. Defenders should add www.gold-idn.com to internal URL filtering and DNS block policies, monitor the associated IP (172.67.171.28) for any future activity, and watch for re‑registration or new hostnames under the same Cloudflare ASN. Continuous verification of the domain’s status is advised, as offline phishing sites often reappear under different subdomains or with altered landing pages.
Data Coverage
Threat Response Pipeline
Blocklist coverage
10 monitored external feeds · stored snapshot Aug 11, 2026
10 monitored external feeds No match
Detection timeline
-
Domain status
Reachable → Unreachable
-
Cloudflare Radar
Cloudflare Radar scan stored · Open scan
-
Domain status
Unreachable → Reachable
Stored Capture
Domain Intelligence
Technical detailsDNS, TLS names and timestamps
ICANN OVERSIGHT
Accreditation and RAA context
Accreditation and RAA context
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
VirusTotal Analysis
Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive