Notification and current-status evidence
The sent-report ledger records the first outgoing report at . A report was sent to the recorded registrar; contact details remain in Domain Intelligence. The latest stored availability evidence still shows the domain reachable; 1 month has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
coin-harvest[.]com
“Coin-harvest”
Resumen de las pruebas
This domain, coin-harvest.com, is flagged as a high-risk cryptocurrency phishing site based on infrastructure analysis and threat intelligence data. Registered on June 21, 2026, through TuringSign Inc. d/b/a Cosmotown, the domain resolves to IP address 194.145.208.36, hosted in the Netherlands under KnownSRV Ltd. The site remains active, returning an HTTP 200 status, and is protected by a Let's Encrypt SSL certificate (YR1). Nameservers ns11.knownsrv.com and ns12.knownsrv.com are consistent with known bulletproof hosting patterns, and the domain appears on at least one security blocklist. Technical indicators include the use of PHP, LiteSpeed, jQuery, Cloudflare Browser Insights, and HTTP/3, suggesting a modern, optimized phishing infrastructure. The MX record points to the domain itself, which is atypical for legitimate services and may indicate email-based credential harvesting or phishing campaigns originating from the same infrastructure. AlienVault OTX lists the domain in two threat intelligence pulses, reinforcing its association with malicious activity. While the page title 'Coin-harvest' implies a focus on cryptocurrency, the exact nature of the phishing scheme—whether targeting wallet credentials, exchange logins, or fraudulent investment offers—remains unconfirmed due to limited analysis of the site's content. Defenders should treat this domain as hostile and prioritize blocking at the DNS, IP, and email gateway levels. Monitoring for outbound connections to 194.145.208.36 or related subdomains is recommended. Given the domain's recent registration and active status, further campaigns using this infrastructure are likely.
Instantánea de evidencia enviada
- Enviado
- Registros del libro
- 1
- ID del caso
PD-20260712-FAF2BD- Título de la página capturada
- Coin-harvest
- Artefacto PDF
- Evidencia en PDF
Fundamento jurídico
Texto completo de la evidencia
Illegal Activities: Active phishing operation targeting victims
Fraud & Deception: Impersonation of legitimate services
Identity Theft: Collection of credentials under false pretenses
Applicable Laws (Unknown):
International Anti-Cybercrime Regulations
Budapest Convention on Cybercrime
Universal Fraud Prevention Laws
Phishing activities violate international cybercrime conventions and Unknown's domestic fraud laws.
Action Required: This evidence-backed report demonstrates clear violations requiring suspension per your policies. Continued hosting exposes your organization to regulatory scrutiny and potential legal liability.
Data Coverage
Proceso de respuesta ante amenazas Pipeline
Cobertura de listas de bloqueo
10 fuentes externas supervisadas · instantánea del 13/08/2026
10 fuentes externas supervisadas Sin coincidencias
Captura guardada
Inteligencia de dominios
Detalles técnicosDNS, nombres TLS y marcas de tiempo
ICANN OVERSIGHT
Acreditación y contexto RAA
Acreditación y contexto RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Tecnologías
5 tecnologías identificadas con alta confianza
Análisis de VirusTotal
¿Te ha afectado esta página web?
Si ingresó credenciales de cuenta, información personal o de pago, o descargó un archivo de este dominio, tome medidas inmediatas. A continuación encontrará recursos que le ayudarán a informar el incidente y protegerse.
Informa a las autoridades locales
Seleccione su país para obtener contactos oficiales de cibercrimen o crear un borrador de queja →.
Comprobar cualquier dominio
Análisis de amenazas utilizando listas de bloqueo almacenadas, WHOIS, DNS y evidencia de escaneo público
Escanear ahoraDenunciar un intento de phishing
Envía los dominios sospechosos a nuestra base de datos de amenazas: protege a la comunidad
DenunciarFlujo de amenazas en tiempo real
Informes de phishing recientes y cambios de disponibilidad observados
MonitorizarMantente informado, mantente a salvo
Supervisa las amenazas en tiempo real o impugna esta entrada si crees que se trata de un falso positivo.