MALICIOUS — CRITICAL
Análisis de phishing y seguridad de arbgovernance.com
arbgovernance[.]
The domain arbgovernance.com was registered on May 11 2026 through GoDaddy.com, LLC.
- VirusTotal
- 13/91
- Blocklists
- 2 · MetaMask, SEAL
- Disponibilidad
- Encubierto · accesible · HTTP 200
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
arbgovernance.com — Encubierto · accesible (HTTP 200). Suplantación de marca: Arb; Tipo de estafa: Credential Phishing. Resumen de las pruebas: VirusTotal 13/91 (alphaMountain.ai, BitDefender, Chong Lua Dao, CRDF, CyRadar); 2 external blocklist matches (MetaMask, SEAL); cloaking observed; PhishDestroy score 100/100. Registrador: GoDaddy.
El análisis detallado de PhishDestroy AI se mantiene en inglés para conservar el registro forense original.
Evidence Analysis
The domain arbgovernance.com was registered on May 11 2026 through GoDaddy.com, LLC. It is currently classified as a high‑risk brand‑impersonation site targeting the ARB brand and is active as of July 12 2026. The page title returned by the web server is “ARB Governance”, matching the legitimate brand’s naming convention and designed to lure victims into credential submission. Infrastructure analysis shows the domain resolves to IP address 76.223.105.230, which is associated with an AWS Global Accelerator endpoint located in the United States. Authoritative name servers are ns29.domaincontrol.com and ns30.domaincontrol.com, both operated by GoDaddy. The site serves over HTTPS using a GoDaddy Secure Certificate Authority – G2 certificate, and HTTP requests receive a 200 OK response. Threat intelligence indicates the site is being used for phishing_login attacks that masquerade as official ARB governance portals. The Gridinsoft trust score is 0 out of 100, and the domain appears on three public blocklists, including PhishDestroy, MetaMask, and SEAL. AlienVault OTX has referenced the domain in one pulse, and VirusTotal reported a single detection out of ninety‑five scanners, confirming at least one security vendor flags the site as malicious. Defenders should immediately block outbound and inbound traffic to arbgovernance.com and its resolved IP address, add the domain to internal blacklist feeds, and monitor DNS queries for the associated name servers. Incident response teams are advised to alert users of the ARB brand about the fraudulent login page, and threat‑intel sharing channels should be updated with the observed indicators to improve detection across the ecosystem.
Stored source results
Recorded verdicts and infrastructure observations for this domain.
Cobertura de los datos12 recorded checks
Proceso de respuesta ante amenazas Pipeline
Estado de la lista de bloqueados pública
Inteligencia de dominios
Detalles técnicosDNS, SAN de SSL, marcas de tiempo
ICANN OVERSIGHT
Acreditación y contexto RAA
Acreditación y contexto RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Análisis de VirusTotal
Análisis de la configuración del sitio
Datos y informes externosIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
Si ingresó credenciales de cuenta, información personal o de pago, o descargó un archivo de este dominio, tome medidas inmediatas. A continuación encontrará recursos que le ayudarán a informar el incidente y protegerse.
Informa a las autoridades locales
Seleccione su país para obtener contactos oficiales de cibercrimen o crear un borrador de queja →.