Notification and current-status evidence
The sent-report ledger records the first outgoing report at .
The recorded recipient is op_ct@cosmotown.com.
The latest stored availability evidence still shows the domain reachable; 8 days has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
openvoicehub[.]info
“One moment, please...”
This domain, openvoicehub.info, is currently flagged as a generic phishing threat and remains active as of the report date of August 06, 2026. The domain was created on April 27, 2026, and is registered through TuringSign Inc. d/b/a Cosmotown. Infrastructure analysis reveals that the domain resolves to the IP address 103.120.48.245. Notably, the nameservers for the domain are listed as not found, which may indicate misconfiguration or recent changes in DNS hosting.
The domain appears on one security blocklist and is actively blocked by PhishDestroy, a security vendor. VirusTotal has scanned the domain with 91 vendors, and currently zero flag it as malicious; however, the absence of detections is not proof that the domain is safe. The registrant information is not detailed beyond the registrar, and the hosting provider and ASN for the IP address are not specified in the available intelligence. The page title and specific content of the website have not been analyzed, so exact details of what the phishing attempt entails are not confirmed.
Defenders should treat this domain with caution due to its active status, its presence on a blocklist, and its classification as a generic phishing threat. Recommended actions include monitoring network traffic for connections to 103.120.48.245, reviewing email logs for messages referencing openvoicehub.info, and adding the domain to internal denylists for email and web filtering to prevent potential user exposure. Further investigation is advised to determine the hosting provider details and to analyze the website content for specific phishing tactics, as the current intelligence does not provide enough information to assess the full scope of the threat.
Threat Response Pipeline
Public Blocklist Status
Stored Capture
Domain Intelligence
Technical detailsDNS, SSL SANs, timestamps
ICANN OVERSIGHT
Accreditation and RAA context
Accreditation and RAA context
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
VirusTotal Analysis
Archived Evidence
Evidence & External Reports
PD-20260806-88F0B4 Recipient: op_ct@cosmotown.com Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive