Notification and current-status evidence
The sent-report ledger records the first outgoing report at .
The recorded recipient is abuse@dynadot.com.
The latest stored availability evidence still shows the domain reachable; 4 months has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
lndteam[.]beer
“Server Offline”
lndteam.beer — असत्यापित. ब्रांड प्रतिरूपण: Microsoft; घोटाले का प्रकार: Impersonation. साक्ष्य सारांश: VirusTotal 17/91 (ADMINUSLabs, alphaMountain.ai, BitDefender, Chong Lua Dao, CyRadar); URLQuery 2 alerts; URLScan malicious verdict; Spamhaus DBL_PHISH; 2 external blocklist matches (MetaMask, SEAL); CF Radar malicious; PhishDestroy score 100/100. रजिस्ट्रार: DYNADOT.
मूल फॉरेंसिक रिकॉर्ड सुरक्षित रखने के लिए नीचे का विस्तृत PhishDestroy AI विश्लेषण अंग्रेज़ी में रखा गया है।
This domain, lndteam.beer, is identified as a high-risk phishing site targeting users of the Lightning Network, a layer-2 payment protocol for Bitcoin. The domain impersonates legitimate Lightning Network development teams or service providers, likely aiming to harvest credentials, private keys, or trick users into executing malicious transactions. Given the context of its naming and infrastructure, it may specifically deploy crypto drainer scripts or fake wallet interfaces to siphon funds from victims' cryptocurrency wallets. Analysis indicates the domain was registered on March 25, 2026, through DYNADOT LLC, a registrar frequently associated with malicious domains. It resolves to the IP address 178.16.52.101, hosted by Omegatech LTD in Germany. The domain appears on three security blocklists, including PhishDestroy, MetaMask, and SEAL. VirusTotal reports 20 out of 95 security vendors flagging lndteam.beer as malicious, with detections spanning phishing, fraud, and cryptocurrency-related threats. The SSL certificate is issued by Let's Encrypt, a common choice for both legitimate and malicious sites due to its accessibility and automation. Users who visited lndteam.beer should immediately revoke any permissions granted to the site in browser-based cryptocurrency wallets or extensions. All active sessions should be terminated, and any credentials or private keys entered on the site must be considered compromised. Users are advised to transfer funds from potentially exposed wallets to new, secure addresses and monitor transaction histories for unauthorized activity. System scans using updated security tools are recommended to detect any residual malware or scripts. Network-level blocking of the domain and its associated IP (178.16.52.101) should be implemented to prevent further access.
नेटवर्क सुरक्षा इंटेलिजेंस
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Quad9 DNS | cdnjsdelivr.beer |
malicious | Sinkholed |
| Hagezi Threat Feed | cdnjsdelivr.beer |
malicious | Sinkholed |
धमकी प्रतिक्रिया पाइपलाइन
सार्वजनिक ब्लॉकलिस्ट स्थिति
सहेजा गया कैप्चर
डोमेन इंटेलिजेंस
तकनीकी विवरणडीएनएस, एसएसएल एसएएन, टाइमस्टैम्प
ICANN OVERSIGHT
प्रत्यायन और आरएए संदर्भ
प्रत्यायन और आरएए संदर्भ
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
तकनीकें · 3 identified
Nginx is a web server that can also be used as a reverse proxy, load balancer, mail proxy and HTTP cache.
nginx.org 100% विश्वासHTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org 100% विश्वासCloudflare Browser Insights is a tool that measures the performance of websites from the perspective of users.
www.cloudflare.com 100% विश्वासवायरसटोटल विश्लेषण
साक्ष्य और बाहरी रिपोर्टें
PD-20260325-DEED31 Recipient: abuse@dynadot.com क्या आप इस साइट से प्रभावित हुए?
यदि आपने खाता क्रेडेंशियल, व्यक्तिगत या भुगतान जानकारी दर्ज की है, या इस डोमेन से कोई फ़ाइल डाउनलोड की है, तो तुरंत कार्रवाई करें। घटना की रिपोर्ट करने और अपनी सुरक्षा करने में आपकी सहायता के लिए नीचे संसाधन दिए गए हैं।
अपने स्थानीय अधिकारियों को रिपोर्ट करें
आधिकारिक साइबर अपराध संपर्क, या एक शिकायत ड्राफ्ट बनाएं → प्राप्त करने के लिए अपना देश चुनें।
किसी भी डोमेन की जाँच करें
संग्रहीत ब्लॉकलिस्ट, WHOIS, DNS और सार्वजनिक स्कैन साक्ष्य का उपयोग करके खतरे का विश्लेषण
अभी स्कैन करेंफ़िशिंग की रिपोर्ट करें
संदिग्ध डोमेन हमारे थ्रेट डेटाबेस में जमा करें — समुदाय की सुरक्षा करें
रिपोर्ट करेंसीधा खतरा फीड
हाल की फ़िशिंग रिपोर्टें और उपलब्धता में परिवर्तन देखे गए
निगरानी करेंजानकारी में रहें, सुरक्षित रहें
लाइव खतरों की निगरानी करें या यदि आपको लगता है कि यह एक गलत सकारात्मक है तो इस लिस्टिंग को चुनौती दें।