promptai[.]network
“$PROMPT — Autonomous Research Agent”
Analysis of the domain promptai.network indicates it was operating as a generic phishing site targeting users with a false 'Autonomous Research Agent' service. The domain, registered on February 22, 2026, through NiceNIC International Group Co., Limited, resolved to the IP address 35.157.26.135, hosted on Amazon.com, Inc. infrastructure (AS16509) in Germany. The site presented a page title of '$PROMPT — Autonomous Research Agent,' suggesting an attempt to impersonate a legitimate research or AI-driven service, though no specific brand affiliation was confirmed in available data. Infrastructure analysis reveals the use of Netlify for hosting and HSTS implementation, alongside nameservers managed by NS1 (dns1-4.p03.nsone.net).
The SSL certificate was issued by Let's Encrypt, a common but not inherently malicious provider. Detection data shows the domain was flagged by two of 95 security vendors on VirusTotal and appears on at least one security blocklist, including PhishDestroy. Gridinsoft assigned a trust score of 0/100, further indicating elevated risk. The domain was taken offline prior to July 24, 2026, though residual DNS records may persist.
Defenders should treat any residual resolution or cached content as malicious and prioritize blocking the domain, its resolved IP, and associated nameservers in perimeter defenses. While the exact phishing mechanism remains unconfirmed due to the site's offline status, the combination of low trust scores, blocklist inclusion, and impersonation of an AI-related service warrants continued monitoring for related infrastructure or resurfacing activity. No evidence links this domain to a specific phishing kit or known threat actor group at this time.
Network Security Intelligence Registrar context
Threat Response Pipeline
Public Blocklist Status
Stored Capture
Domain Intelligence
Technical detailsDNS, SSL SANs, timestamps
ICANN OVERSIGHT
Accreditation and RAA context
Accreditation and RAA context
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Latest Classified Outcome 2026-09-01 02:31:10 UTC
Technologies · 2 identified
Platform for deploying and hosting modern web applications.
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
VirusTotal Analysis
Archived Evidence
Site Performance Analysis
Google PageSpeed Insights — mobile performance audit of promptai.network · checked Mar 2, 2026
Evidence & External Reports
Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive