Notification and current-status evidence
The sent-report ledger records the first outgoing report at . A report was sent to the recorded registrar; contact details remain in Domain Intelligence. The latest stored availability evidence still shows the domain reachable; 19 days has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
sinorandacao[.]net
“Infraestrutura Resiliente & Escala Global | Sino Randação”
Evidence Summary
Analysis of sinorandacao.net indicates the domain is being used for a credential‑harvesting phishing operation. The domain was registered on 22 June 2026 through Dynadot Inc. and is hosted on the Cloudflare network, as evidenced by the authoritative nameservers drew.ns.cloudflare.com and grace.ns.cloudflare.com. DNS resolution points to IP address 104.21.78.129, which is associated with Cloudflare’s edge infrastructure. The domain remains active as of the report date 23 July 2026.
VirusTotal records show that the domain has been scanned by 95 security vendors, yet none have generated a detection. While the absence of detections does not confirm safety, it indicates that automated signatures have not yet identified malicious payloads linked to this host. The domain is listed on one public security blocklist and is actively blocked by the PhishDestroy service, suggesting that threat‑intel feeds have flagged it as malicious. No public information about the site’s SSL certificate, HTTP response codes, page title, or content has been released, so the exact appearance and targeted brand remain unknown.
Consequently, the confidence in the phishing classification derives primarily from the blocklist entry and the recent registration pattern typical of fast‑flux or throwaway domains used in credential‑stealing campaigns. Defenders should add sinorandacao.net to network‑level deny lists, enforce DNS sink‑holing for the resolved IP, and monitor for outbound connections to Cloudflare edge nodes that resolve to the same address. Continuous re‑scanning with multi‑vendor services is advised, as future updates may reveal signatures or behavioural indicators. Organizations that rely on email or web gateways should ensure that URL filtering rules include this domain to prevent end‑user exposure.
Submitted Evidence Snapshot
- Sent
- Ledger records
- 1
- Case ID
PD-20260723-F6F766- Captured page title
- Sino Randação – Plataforma de Trading com IA de Confiança
- PDF artifact
- PDF evidence
Full evidence text
Policy Violations: Acceptable Use forbids illegal content; Spam & Abuse Policy prohibits phishing, fraud, malware; Dynadot may disable DNS and suspend domains
Applicable Laws: CFAA 18 U.S.C. §1030, Wire Fraud 18 U.S.C. §1343, CAN-SPAM Act
Data Coverage
Threat Response Pipeline
Blocklist coverage
10 monitored external feeds · stored snapshot Aug 12, 2026
8 monitored external feeds No match
Stored Capture
Domain Intelligence
Technical detailsDNS, TLS names and timestamps
ICANN OVERSIGHT
Accreditation and RAA context
Accreditation and RAA context
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Technologies
4 high-confidence technologies identified
VirusTotal Analysis
Archived Evidence
Site Performance Analysis
Google PageSpeed Insights — mobile performance audit of sinorandacao.net · checked Jul 23, 2026
Site Configuration Analysis
Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive