nadopro[.]network
Nadopro.network, a phishing domain, is currently offline but has been flagged by 3 out of 91 vendors on VirusTotal. The domain was hosted by Cloudflare, Inc., with an IP address located in Canada. It was registered through NICENIC INTERNATIONAL GROUP CO., LIMITED, and used a Let's Encrypt SSL certificate. Despite its offline status, it remains listed on public blocklists, including PhishDestroy, MetaMask, and SEAL.
The domain's presence on multiple blocklists indicates its involvement in malicious activities, likely targeting unsuspecting users through phishing schemes. The use of a Let's Encrypt SSL certificate suggests an attempt to appear legitimate and secure, a common tactic among phishing sites to gain user trust. The quick takedown of this domain highlights the effectiveness of monitoring and reporting efforts by organizations like PhishDestroy.
Although nadopro.network is no longer active, its detection by several security vendors underscores the importance of proactive threat intelligence. Phishing domains often exploit the gap between their registration and detection by antivirus databases, making early identification crucial. The inclusion of this domain in public blocklists serves as a warning to users and organizations to remain cautious of similar threats.
Network Security Intelligence Registrar context
Threat Response Pipeline
Blocklist coverage
10 sources · synchronized Aug 10, 2026
Detection timeline
-
Availability
stage4.timeline.first_value
993d00c35140 -
Availability
stage4.timeline.transition
55c982a6c746 -
Availability
stage4.timeline.transition
83374d9d652c -
Availability
stage4.timeline.transition
d4e35878586d -
Availability
stage4.timeline.transition
7cebcfd4071c -
Availability
stage4.timeline.transition
0f8c86a4ae5e -
Availability
stage4.timeline.transition
ca255b61650a -
Availability
stage4.timeline.transition
95304baea8e7 -
Availability
stage4.timeline.transition
3281fd349c87 -
Availability
stage4.timeline.transition
3920199571e3
Domain Intelligence
Technical detailsDNS, TLS names and timestamps
ICANN OVERSIGHT
Accreditation and RAA context
Accreditation and RAA context
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
VirusTotal Analysis
Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive