Notification and current-status evidence
The sent-report ledger records the first outgoing report at .
The recorded recipient is abuse@virtualine.org.
The latest stored availability evidence still shows the domain reachable; 28 days has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
invitelink[.]one
“Default Web Site Page”
Analysis of invitelink.one indicates a high-risk phishing domain targeting cryptocurrency users, currently active as of July 20, 2026. The domain was registered on June 12, 2026, through NameSilo, LLC, and is hosted on IP address 130.12.180.78, utilizing Cloudflare nameservers (earl.ns.cloudflare.com, jule.ns.cloudflare.com). It appears on three security blocklists, including PhishDestroy, MetaMask, and SEAL, which specifically flag cryptocurrency-related threats. While no detections are currently recorded by VirusTotal vendors, this absence does not confirm safety, particularly given the domain's presence on specialized blocklists. Infrastructure analysis reveals reliance on Cloudflare for DNS resolution, a common tactic to obscure hosting origins and evade takedowns. The domain's registration age (under six weeks) aligns with typical phishing campaign lifecycles, where rapid deployment and short operational windows are standard. Defenders should treat this domain as an active threat, particularly for users interacting with cryptocurrency platforms. Immediate action includes blocking the domain and IP at network and endpoint levels, monitoring for related subdomains or redirects, and alerting users to potential credential harvesting or wallet-draining attempts. Further investigation into the hosting IP and associated domains may reveal broader campaign infrastructure.
Network Security Intelligence Registrar context
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Hagezi Threat Feed | invitelink.one |
malicious | Sinkholed |
Threat Response Pipeline
Public Blocklist Status
Stored Capture
Domain Intelligence
Technical detailsDNS, SSL SANs, timestamps
ICANN OVERSIGHT
Accreditation and RAA context
Accreditation and RAA context
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
VirusTotal Analysis
Archived Evidence
Evidence & External Reports
PD-20260720-101188 Recipient: abuse@virtualine.org Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive