Notification and current-status evidence
The sent-report ledger records the first outgoing report at .
The recorded recipient is abuse@deneva.co.id.
The latest stored availability evidence still shows the domain reachable; 1 month has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
web-3web.com
“Home - web-3 Web - A crypto buy and sell marketplace”
The domain web-3web.com was registered on February 10, 2026 through GMO Internet, Inc. and presently resolves to the IP address 103.147.154.221.
The detailed PhishDestroy AI analysis below remains in English to preserve the original forensic record.
Evidence Summary
The domain web-3web.com was registered on February 10, 2026 through GMO Internet, Inc. and presently resolves to the IP address 103.147.154.221. DNS records show authoritative name servers ns1.domainesia.net and ns2.domainesia.net, indicating the use of a third‑party DNS provider. As of the report date, the domain remains active and continues to resolve, suggesting the infrastructure is still operational. VirusTotal scans have identified the domain as malicious in 2 of 91 security vendor engines, providing a modest but concrete indication of phishing‑related activity.
Independent threat‑intelligence feeds have placed the domain on a single security blocklist, and it is explicitly listed as blocked by the PhishDestroy service, confirming that at least one anti‑phishing organization has taken action against it. No public information is available regarding the website’s page title, SSL certificate details, or the specific content hosted, leaving the exact phishing lure and target brand undefined. Consequently, the precise technique employed (e.g., credential harvesting page, credential‑stealing redirect) cannot be confirmed without direct content analysis.
Defenders should prioritize immediate mitigation: add web-3web.com and its resolving IP 103.147.154.221 to network‑level blocklists, update DNS filtering policies to deny queries for the domain, and monitor for any related sub‑domains or infrastructure changes. Continuous re‑scanning of the domain through multi‑vendor services is advised to capture any escalation in detection counts. Given the recent creation date and limited detection footprint, the threat remains high due to its active status and confirmed phishing classification, warranting proactive blocking and ongoing observation.
Detection timeline
-
Domain status
Unreachable → Reachable
-
Domain status
Reachable → Unreachable
-
First recorded
First stored value: Reachable
Threat Response Pipeline
Public Blocklist Status
Submitted Evidence Snapshot
- Sent
- Ledger records
- 1
- Case ID
PD-20260727-8DF780
Blocklist coverage
11 monitored external feeds · stored snapshot Sep 10, 2026
Stored Capture
Domain Intelligence
Technical detailsDNS, SSL SANs, timestamps
ICANN OVERSIGHT
Accreditation and RAA context
Accreditation and RAA context
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Technologies · 4 identified
Smartsupp is a live chat tool that offers visitor recording feature.
www.smartsupp.com 100% confidenceHTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org 100% confidenceHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100% confidenceVirusTotal Analysis
Archived Evidence
Technologies
4 high-confidence technologies identified
Evidence & External Reports
PD-20260727-8DF780 Recipient: abuse@deneva.co.id Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive