Notification and current-status evidence
The sent-report ledger records the first outgoing report at .
The recorded recipient is abuse@dynadot.com.
The latest stored availability evidence still shows the domain reachable; 4 months has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
portal-zestprotocol[.]xyz
“portal-zestprotocol.xyz | 504: Gateway time-out”
portal-zestprotocol.xyz — Belum terverifikasi. Jenis penipuan: Fake Exchange. Ringkasan bukti: VirusTotal 5/91 (alphaMountain.ai, Chong Lua Dao, Forcepoint ThreatSeeker, Gridinsoft, SOCRadar); URLQuery 1 alert; 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 69/100. Registrar: Dynadot.
Analisis terperinci PhishDestroy AI di bawah tetap berbahasa Inggris untuk menjaga catatan forensik asli.
Portal-zestprotocol.xyz has been flagged by PhishDestroy as an active brand spoofing phishing domain designed to impersonate a legitimate financial protocol portal. This threat specifically targets unsuspecting users by mimicking well-known finance platforms to steal login credentials and sensitive financial information. The domain was registered only days ago, on March 25, 2026, which indicates a highly opportunistic and potentially short-lived campaign aimed at capitalizing on recent trends or hype around decentralized finance protocols. Users accessing this site risk immediate credential theft or malware exposure through deceptive login interfaces disguised as legitimate portals. PhishDestroy identifies this domain presents active brand spoofing risks with minimal detection coverage at present. VirusTotal currently shows 4 out of 95 security engines flagging the domain. The site was registered through Dynadot LLC and resolved to IP address 172.67.143.178. It operates under a valid Let's Encrypt SSL certificate, which may give false reassurance of legitimacy. Despite no blocklist entries detected yet, the domain’s recent creation date and low detection rate suggest it is either newly deployed or flying under the radar. The absence of historical trust data and the use of a content delivery network IP (Cloudflare AS13335) increases opacity around hosting infrastructure and ownership. These technical indicators—particularly the fresh registration, uncommon domain syntax, and valid-but-abused SSL certificate—are consistent with active phishing infrastructure designed for credential harvesting. In response to this brand spoofing threat, users should immediately cease all interaction with portal-zestprotocol.xyz and avoid entering any credentials or personal information. Organizations are advised to block both the domain and its underlying IP address (172.67.143.178) at network and DNS levels. Shared threat intelligence should be updated with the unique seed identifier 0359c6 to prevent cross-contamination. Security teams must monitor for lateral movement if credentials were previously entered, as stolen login data may be used in follow-up attacks. This domain exemplifies how attackers leverage legitimate-looking domains and valid SSL certificates to bypass security controls and deceive users, reinforcing the need for layered defenses including user awareness training, real-time phishing detection, and proactive domain monitoring. Due to the evolving nature of this threat and low initial detection rates, continuous monitoring and rapid response are critical.
Intelijen Keamanan Jaringan
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DNS4EU | llama-rpc-mainnet.com |
malicious | Sinkholed |
Alur Tanggapan Ancaman Pipeline
Status Daftar Blokir Publik
Tangkapan tersimpan
Intelijen Domain
Rincian teknisDNS, SAN SSL, cap waktu
ICANN OVERSIGHT
Akreditasi dan konteks RAA
Akreditasi dan konteks RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Teknologi · 2 identified
Web infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
Analisis VirusTotal
Bukti & Laporan Eksternal
PD-20260326-569B22 Recipient: abuse@dynadot.com Apakah Anda Terpengaruh oleh Situs Ini?
Jika Anda memasukkan kredensial akun, informasi pribadi atau pembayaran, atau mengunduh file dari domain ini, segera ambil tindakan. Di bawah ini adalah sumber daya untuk membantu Anda melaporkan insiden tersebut dan melindungi diri Anda sendiri.
Laporkan kepada Pihak Berwenang di Daerah Anda
Pilih negara Anda untuk mendapatkan kontak resmi kejahatan dunia maya, atau membuat draf pengaduan →.
Periksa Domain Apa Pun
Analisis ancaman menggunakan daftar blokir yang disimpan, WHOIS, DNS, dan bukti pemindaian publik
Pindai SekarangLaporkan Phishing
Laporkan domain yang mencurigakan ke basis data ancaman kami — lindungi komunitas
LaporanPemberitahuan Ancaman Real-Time
Laporan phishing terbaru dan perubahan ketersediaan yang diamati
PantauTetap Terinformasi, Tetap Aman
Pantau ancaman secara langsung atau ajukan keberatan terhadap daftar ini jika Anda yakin ini merupakan false positive