Notification and current-status evidence
The sent-report ledger records the first outgoing report at .
The recorded recipient is abuse@nicenic.net.
The latest stored availability evidence still shows the domain reachable; 6 months has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
guiaveiculoonline[.]com
“ESCRITORIO ORIGINAL”
guiaveiculoonline.com — Terselubung · dapat dijangkau. Jenis penipuan: Investment Scam. Ringkasan bukti: VirusTotal 6/91 (alphaMountain.ai, CRDF, Fortinet, Gridinsoft, Seclookup); URLQuery 1 alert; Spamhaus DBL_PHISH; cloaking observed; PhishDestroy score 72/100. Registrar: NiceNIC.
Analisis terperinci PhishDestroy AI di bawah tetap berbahasa Inggris untuk menjaga catatan forensik asli.
This domain, guiaveiculoonline.com, is flagged as a brand impersonation threat targeting Aave, a decentralized finance protocol. Analysis indicates the site presented itself as an official Aave interface, likely designed to harvest credentials or facilitate cryptocurrency theft. The page title "ESCRITORIO ORIGINAL" suggests an attempt to mimic legitimate login portals, a common tactic in phishing campaigns targeting cryptocurrency users. No specific drainer kit signatures were identified, but the infrastructure aligns with known phishing patterns observed in DeFi-related attacks. Infrastructure analysis reveals the domain was registered on February 21, 2026, through NiceNIC International Group Co., Limited, a registrar frequently associated with malicious domains. It resolved to the IP address 188.114.96.3, which is part of a network known for hosting phishing and scam sites. The domain appears on one security blocklist, with a VirusTotal detection score of 5/95 security vendors flagging it as malicious. The SSL certificate was issued by Google Trust Services, a common practice among threat actors to lend legitimacy to phishing sites. No Google Safe Browsing (GSB) listing was recorded, indicating the domain may have been taken offline before broader detection occurred. The domain is currently offline, reducing immediate risk to users. However, the infrastructure remains a potential threat, as domains registered through this registrar and resolving to similar IP ranges have been reactivated in past campaigns. Users who interacted with the site should assume credential compromise and take immediate action, including revoking wallet approvals and monitoring for unauthorized transactions. Organizations should update blocklists to include this domain and its associated IP to prevent future access attempts. The elevated risk level is maintained due to the domain's recent activity and the persistent threat posed by similar infrastructure.
Intelijen Keamanan Jaringan Registrar context
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Hagezi Threat Feed | guiaveiculoonline.com |
malicious | Sinkholed |
Alur Tanggapan Ancaman Pipeline
Status Daftar Blokir Publik
Tangkapan tersimpan
Intelijen Domain
Rincian teknisDNS, SAN SSL, cap waktu
ICANN OVERSIGHT
Akreditasi dan konteks RAA
Akreditasi dan konteks RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Latest Classified Outcome 2026-08-15 02:42:12 UTC
Teknologi · 3 identified
Performance monitoring tool that measures website speed from real users.
www.cloudflare.comWeb infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
Analisis VirusTotal
Bukti Terarsip
Analisis Performa Situs
Google PageSpeed Insights — mobile performance audit of guiaveiculoonline.com · checked Jun 26, 2026
Bukti & Laporan Eksternal
PD-20260214-68709A Recipient: abuse@nicenic.net Apakah Anda Terpengaruh oleh Situs Ini?
Jika Anda memasukkan kredensial akun, informasi pribadi atau pembayaran, atau mengunduh file dari domain ini, segera ambil tindakan. Di bawah ini adalah sumber daya untuk membantu Anda melaporkan insiden tersebut dan melindungi diri Anda sendiri.
Laporkan kepada Pihak Berwenang di Daerah Anda
Pilih negara Anda untuk mendapatkan kontak resmi kejahatan dunia maya, atau membuat draf pengaduan →.
Periksa Domain Apa Pun
Analisis ancaman menggunakan daftar blokir yang disimpan, WHOIS, DNS, dan bukti pemindaian publik
Pindai SekarangLaporkan Phishing
Laporkan domain yang mencurigakan ke basis data ancaman kami — lindungi komunitas
LaporanPemberitahuan Ancaman Real-Time
Laporan phishing terbaru dan perubahan ketersediaan yang diamati
PantauTetap Terinformasi, Tetap Aman
Pantau ancaman secara langsung atau ajukan keberatan terhadap daftar ini jika Anda yakin ini merupakan false positive