Notification and current-status evidence
The sent-report ledger records the first outgoing report at . A report was sent to the recorded registrar; contact details remain in Domain Intelligence. The latest stored availability evidence still shows the domain reachable; 25 days has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
ndrt[.]ink
“DAS Licence Control”
Evidence Summary
Analysis of the domain ndrt.ink shows an active malicious infrastructure that meets the criteria for a high‑risk generic phishing operation. The domain resolves to the IPv4 address 159.198.32.222 and was registered on February 5 2026 through Namecheap Inc, using the authoritative name servers dns1.registrar-servers.com and dns2.registrar-servers.com. VirusTotal scans have returned detections from 20 of 91 security vendors, indicating that the domain is already recognized as malicious by multiple AV engines. AlienVault OTX lists the domain in four independent threat‑intel pulses, further corroborating its use in phishing campaigns. The combination of recent registration, active DNS resolution, and multi‑vendor detections suggests a deliberate, ongoing campaign rather than a transient test site. At present, no additional contextual data such as payload samples, targeted brands, or phishing page content has been disclosed, leaving the exact lure and victim profile uncertain. Defenders should block outbound traffic to 159.198.32.222 and implement DNS filtering for ndrt.ink across enterprise resolvers. Security operations teams should monitor for any email or web‑based indicators that reference the domain, and threat‑intel feeds should be updated to include the observed OTX pulses. Continuous re‑evaluation is advised as new artifacts become available.
Submitted Evidence Snapshot
- Sent
- Ledger records
- 1
- Case ID
PD-20260718-695638- Captured page title
- 404 Not Found
Full evidence text
Policy Violations: Domain Registration Agreement prohibits hacking, misuse of domain to conduct attacks, scam and fraudulent activities; AUP allows immediate suspension
Applicable Laws: CFAA 18 U.S.C. §1030, Wire Fraud 18 U.S.C. §1343, CAN-SPAM Act
Data Coverage
Network Security Intelligence
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Cloudflare DNS | ndrt.ink |
malicious | Sinkholed |
| Hagezi Threat Feed | ndrt.ink |
malicious | Sinkholed |
| DNS4EU | ndrt.ink |
malicious | Sinkholed |
| Quad9 DNS | ndrt.ink |
malicious | Sinkholed |
Threat Response Pipeline
Blocklist coverage
10 monitored external feeds · stored snapshot Aug 12, 2026
10 monitored external feeds No match
Detection timeline
-
VirusTotal
18 → 20
Stored Capture
Domain Intelligence
Technical detailsDNS, TLS names and timestamps
ICANN OVERSIGHT
Accreditation and RAA context
Accreditation and RAA context
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
VirusTotal Analysis
Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive