MALICIOUS — HIGH
Pemeriksaan phishing dan keamanan riowax.com
riowax[.]
The domain riowax.com is a generic phishing site designed to deceive users through social media phishing tactics.
- VirusTotal
- 2/91
- Blocklists
- No stored match
- Ketersediaan
- Terakhir diketahui aktif · HTTP 200
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Notification and current-status evidence
The sent-report ledger records the first outgoing report at .
It contains 6 outgoing records; the latest is dated . The recorded recipient is abuse@dynadot.com.
The latest stored availability evidence still shows the domain reachable; 5 months has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
Jump to section
riowax.com — Terakhir diketahui aktif (HTTP 200). Jenis penipuan: Social Media Phishing. Ringkasan bukti: VirusTotal 2/91 (Gridinsoft, SOCRadar); PhishDestroy score 66/100. Registrar: Dynadot.
Analisis terperinci PhishDestroy AI di bawah tetap berbahasa Inggris untuk menjaga catatan forensik asli.
Evidence Analysis
The domain riowax.com is a generic phishing site designed to deceive users through social media phishing tactics. It does not impersonate a specific brand or use a known drainer kit. As of the latest verification, riowax.com has been taken offline, reducing immediate risk to users, though its previous activity remains under investigation.
Technical indicators show that riowax.com had 0 of 95 VirusTotal vendors flagging it as malicious, and Google Safe Browsing did not list it as unsafe. The domain was registered through Dynadot LLC on March 04, 2026, and resolved to the IP address 23.35.29.9, hosted by Akamai Technologies in the US. It appeared on one security blocklist (PhishDestroy) and used an SSL certificate issued by Go Daddy Secure Certificate Authority - G2. The observed page title was 'riowax.com', and the site employed technologies such as PHP, Apache HTTP Server, jQuery, and Google Tag Manager. MX records pointed to 'park-mx.above.com', with nameservers at '5014.ns1.abovedomains.com' and '5014.ns2.abovedomains.com'.
Users who suspect they interacted with riowax.com should change any exposed credentials immediately, enable two-factor authentication on all accounts, and monitor for unauthorized activity. Report the domain to platforms like PhishTank, Google Safe Browsing, or local cybersecurity authorities to aid in broader mitigation efforts. If financial or cryptocurrency accounts were involved, review transaction histories and consider revoking any suspicious token approvals.
Stored source results
Recorded verdicts and infrastructure observations for this domain.
Cakupan data12 recorded checks
Alur Tanggapan Ancaman Pipeline
Status Daftar Blokir Publik
Tangkapan tersimpan
Intelijen Domain
Rincian teknisDNS, SAN SSL, cap waktu
ICANN OVERSIGHT
Akreditasi dan konteks RAA
Akreditasi dan konteks RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Riwayat Laporan Penyalahgunaan · 6 stored reports over 68 days · click to expand
-
Report #1 Feb 26, 2026 · 22:39 UTCPhishing Abuse Report: riowax[.]comabuse@dynadot.com
-
Report #2 ICANN CC 99h still active Mar 3, 2026 · 01:46 UTCESCALATION #2 (99h active): Phishing - riowax[.]comabuse@dynadot.com abuse@verisign-grs.com compliance@icann.org
-
Report #3 ICANN CC 1314h still active Apr 22, 2026 · 20:15 UTCESCALATION #3 (1314h active): Phishing - riowax[.]comabuse@dynadot.com abuse@verisign-grs.com compliance@icann.org
-
Report #4 ICANN CC 1407h still active Apr 26, 2026 · 17:16 UTCESCALATION #4 (1407h active): Phishing - riowax[.]comabuse@dynadot.com abuse@verisign-grs.com compliance@icann.org
-
Report #5 ICANN CC 1456h still active Apr 28, 2026 · 18:20 UTCESCALATION #5 (1456h active): Phishing - riowax[.]comabuse@dynadot.com abuse@verisign-grs.com compliance@icann.org
-
Report #6 ICANN CC 1614h still active May 5, 2026 · 08:36 UTCESCALATION #6 (1614h active): Phishing - riowax[.]comabuse@dynadot.com abuse@verisign-grs.com compliance@icann.org
Teknologi · 7 identified
Server-side scripting language designed for web development.
Most widely used open-source HTTP server software.
Legacy JavaScript library — DOM manipulation and AJAX helpers. Still widely present on older sites.
Legacy JavaScript library — DOM manipulation and AJAX helpers. Still widely present on older sites.
Fast, small JavaScript library simplifying HTML manipulation, event handling, and Ajax.
Tag management system for deploying marketing and analytics tags.
tagmanager.google.comAnalisis VirusTotal
Analisis Performa Situs
Google PageSpeed Insights — mobile performance audit of riowax.com · checked Mar 5, 2026
Bukti & Laporan EksternalIndependent lookups and source reports
PD-1772502396-riowax.com Recipient: abuse@dynadot.com Victim safety and official reportingImmediate actions and verified reporting channels
Jika Anda memasukkan kredensial akun, informasi pribadi atau pembayaran, atau mengunduh file dari domain ini, segera ambil tindakan. Di bawah ini adalah sumber daya untuk membantu Anda melaporkan insiden tersebut dan melindungi diri Anda sendiri.
Laporkan kepada Pihak Berwenang di Daerah Anda
Pilih negara Anda untuk mendapatkan kontak resmi kejahatan dunia maya, atau membuat draf pengaduan →.