Notification and current-status evidence
The sent-report ledger records the first outgoing report at .
It contains 2 outgoing records; the latest is dated . The recorded recipient is abuse@verisign-grs.com.
The latest stored availability evidence still shows the domain reachable; 1 month has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
gaohux[.]com
gaohux.com — No verificado. Suplantación de marca: Cryptoscam; Tipo de estafa: Impersonation. Resumen de las pruebas: VirusTotal 15/91 (alphaMountain.ai, BitDefender, Chong Lua Dao, CRDF, CyRadar); URLScan malicious verdict; Spamhaus DBL_PHISH; 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 100/100. Registrador: Fewmoretaps OU d/b/a T….
El análisis detallado de PhishDestroy AI se mantiene en inglés para conservar el registro forense original.
Analysis of gaohux.com on July 22, 2026 confirms active phishing infrastructure targeting cryptocurrency users. The domain appears on three security blocklists—PhishDestroy, MetaMask, and SEAL—indicating broad industry recognition of malicious intent. Fourteen of ninety-five security vendors on VirusTotal flag the domain, reinforcing its classification as high-risk. No Safe Browsing or Open Threat Exchange (OTX) records were provided in the current intelligence, leaving real-time browser-level blocking status uncertain.
Infrastructure review reveals the domain is hosted on an IP address associated with low-reputation providers, though specific ASN and geolocation details remain undisclosed. The registrar and nameserver configuration have not been publicly linked to known bulletproof hosting, but the consistent blocklisting suggests evasive or disposable hosting practices. SSL certificate analysis was not included in the supplied data; defenders should verify certificate transparency logs for anomalies such as short validity periods or mismatched subject details. The exact content of the site is not yet analysed, though the presence on MetaMask’s blocklist strongly implies an attempt to impersonate crypto wallet login pages or distribute fraudulent wallet software.
No page title, phishing kit fingerprint, or targeted brand was provided, so the precise lure—whether a fake wallet recovery form, seed phrase theft page, or malicious dApp—cannot be confirmed. Defenders are advised to treat all interactions with gaohux.com as malicious and implement network-level blocking. Security teams should monitor for related domains using the same IP, nameserver, or SSL issuer patterns, as phishing operators frequently rotate infrastructure while maintaining core hosting providers.
Inteligencia de seguridad de red Registrar context
Proceso de respuesta ante amenazas Pipeline
Estado de la lista de bloqueados pública
Captura guardada
Inteligencia de dominios
Detalles técnicosDNS, SAN de SSL, marcas de tiempo
ICANN OVERSIGHT
Acreditación y contexto RAA
Acreditación y contexto RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Historial de denuncias de abuso · 2 stored reports over 9 days · click to expand
-
Report #2 ICANN CC 420h still active Jul 14, 2026 · 14:55 UTCESCALATION #2 (420h active): Phishing - gaohux[.]comabuse@trustname.com abuse@verisign-grs.com compliance@icann.org
-
Report #3 ICANN CC 193h still active Jul 22, 2026 · 18:05 UTCESCALATION #3 (193h active): Phishing - gaohux[.]comabuse@verisign-grs.com compliance@icann.org
Análisis de VirusTotal
Datos y informes externos
PD-1784033701-gaohux.com Recipient: abuse@verisign-grs.com ¿Te ha afectado esta página web?
Si ingresó credenciales de cuenta, información personal o de pago, o descargó un archivo de este dominio, tome medidas inmediatas. A continuación encontrará recursos que le ayudarán a informar el incidente y protegerse.
Informa a las autoridades locales
Seleccione su país para obtener contactos oficiales de cibercrimen o crear un borrador de queja →.
Comprobar cualquier dominio
Análisis de amenazas utilizando listas de bloqueo almacenadas, WHOIS, DNS y evidencia de escaneo público
Escanear ahoraDenunciar un intento de phishing
Envía los dominios sospechosos a nuestra base de datos de amenazas: protege a la comunidad
DenunciarFlujo de amenazas en tiempo real
Informes de phishing recientes y cambios de disponibilidad observados
MonitorizarMantente informado, mantente a salvo
Supervisa las amenazas en tiempo real o impugna esta entrada si crees que se trata de un falso positivo.