mrrefsite[.]global
“Юридическая Помощь - Ваш Защитник в Правовых Вопросах”
The domain mrrefsite.global has been identified as a generic phishing threat and remains active. Analysis suggests that this domain may be leveraged for fraudulent activities, though it does not currently impersonate a specific brand.
Technical indicators show that mrrefsite.global is registered through PDR Ltd. d/b/a PublicDomainRegistry.com and was created on June 24, 2026. It resolves to the IP address 188.114.96.3, which is located in the United States and is associated with AS13335 Cloudflare, Inc. The domain appears on one security blocklist and has been flagged by 1 out of 95 VirusTotal security vendors, indicating a low level of detection and awareness among the security community. Notably, the domain is currently blocked by PhishDestroy, providing an additional layer of identification for security professionals.
Given the current status of mrrefsite.global as active, it is recommended that users exercise caution when encountering this domain. Organizations should implement domain filtering based on security blocklist data and ensure that security awareness training is updated to include this domain. Continuous monitoring of domain activities and associated IP addresses is crucial to detect any potential changes in threat behavior. Users should be discouraged from entering sensitive information on this domain and report any suspicious activities to their respective cybersecurity teams.
Threat Response Pipeline
Public Blocklist Status
Stored Capture
Domain Intelligence
Technical detailsDNS, SSL SANs, timestamps
ICANN OVERSIGHT
Accreditation and RAA context
Accreditation and RAA context
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
VirusTotal Analysis
Evidence & External Reports
PD-20260625-D6147C Recipient: abuse@publicdomainregistry.com Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive