VirusTotal
1 / 89
The sent-report ledger records the first outgoing report at .
The recorded recipient is abuse+registry@porkbun.com.
The latest stored availability evidence still shows the domain reachable; 8 months has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| YARAhub by abuse.ch | thorwap.finance/after.js |
malware | Detects file containing Telegram Bot API |
| OpenDNS | api.ceooflidare.icu |
phishing | Phishing Block |
The domain thorwap.finance, associated with a generic phishing operation, has a high threat score of 75/100 and is currently down. It has been flagged as malicious by 4 out of 95 security vendors, including Gridinsoft and SOCRadar, and is listed on one public blocklist, though Google Safe Browsing has not flagged it.
Registered with Porkbun LLC, the domain was created on February 21, 2026, and was first detected on February 3, 2026. The hosting IP is 172.67.182.116. The operational status and detection metrics indicate a significant threat level, warranting immediate action. Block the domain at the perimeter and submit a report to the registrar's abuse desk.
Stored crawler-versus-browser observations for this host, plus a live fingerprint check for Keitaro-style traffic distribution systems.
cloudflareScanner note: cloudflare_challenge: raw=cf_challenge; http=403; via=https_proxy; server=cloudflare
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Edge-IP reputation is not attributed to this domain.
annalise.ns.cloudflare.comLocation describes the IP network.
ed2fef6b910d9b4d5f325f333b021ce7ef91c9f4afcd95df8a9b97d9b5e2875cSaved certificate metadata. Certificate dates without a timezone are shown as stored. Transport encryption does not establish that the site is trustworthy.
Google PageSpeed Insights — mobile performance audit of thorwap.finance · checked Apr 28, 2026
13 recorded events. These records describe collected evidence, outgoing notifications and publication; they do not confirm a complete investigation or a takedown.
We scan suspicious URLs, inspect public results and send evidence through the appropriate abuse-reporting channels. The dated events above show what is recorded for this domain. The directory below explains the wider workflow.
Capture the rendered page, requests and visible infrastructure.
Compare the available engine results and retain the analysis timestamp.
Check whether Google currently lists the URL as unsafe.
Inspect a public scan and its recorded network and classification data.
Look for indicator references and related community intelligence.
Compare archived captures and preserve historical context.
Look for matching indicators and associated threat records.
Inspect certificate records and related hostnames.
Compare security resolver responses and record observed blocking.
Inspect the public DNS, TLS, HTTP and technology surface.
Security services used for scanning, reputation checks and reporting are listed below. A service being listed is not evidence that it received, accepted or acted on this particular domain. Recorded submissions appear in the notification history above.
Reported by 1 community member, first seen Feb 3, 2026
PD-20260203-A9E920 Recipient: abuse+registry@porkbun.com Policy Violations: Acceptable Use Policy (AUP): The domain thorwap.finance is engaged in phishing activities, which are explicitly prohibited under your AUP. This constitutes a direct violation of the policy's stipulation against illegal activities and fraud. Terms of Service (TOS): The continued operation of this domain violates your TOS, which reserves the right to suspend or terminate services for any activities that facilitate deception or fraud. Applicable Laws (Unknown): Computer Fraud and Abuse Act (CFAA): This U.S. federal law prohibits unauthorized access to computers and networks, which is relevant as phishing schemes often involve unauthorized data access. Wire Fraud Statute (18 U.S.C. § 1343): This law criminalizes schemes to defraud individuals or entities via electronic communications, encompassing phishing activities. Anti-Phishing Act of 2004: This legislation specifically targets phishing schemes and imposes penalties for those who engage in such deceptive practices. Regulatory Note: Failure to take immediate action against thorwap.finance may expose your organization to legal liability and regulatory scrutiny. Compliance with your AUP and TOS is essential to mitigate risks associated with hosting malicious content.
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Select your country to get official cybercrime contacts, or create a complaint draft →.
Template-based draft · optional AI wording assistance requires separate consent
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowSubmit suspicious domains to our threat database — protect the community
ReportRecent phishing reports and observed availability changes
MonitorMonitor live threats or contest this listing if you believe it's a false positive