Notification and current-status evidence
The sent-report ledger records the first outgoing report at . A report was sent to the recorded registrar; contact details remain in Domain Intelligence. The latest stored availability evidence still shows the domain reachable; 3 months has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
buyonek[.]com
“Buyone - 로그인”
PhishDestroy identifies buyonek.com as an active generic-phishing domain engineered to deceive users searching for discounted products. The site lures visitors with unrealistically low pricing on a variety of popular items, then harvests login credentials, payment card numbers, and personal information entered on counterfeit checkout forms. Victims who enter data risk immediate financial loss and ongoing identity theft, while the stolen credentials may be sold on dark-web marketplaces or used to take over existing financial accounts.
Technical analysis reveals several red flags within buyonek.com’s infrastructure. The domain was registered on April 26, 2024 through NICENIC INTERNATIONAL GROUP CO., LIMITED, a registrar implicated in past bulk-registration campaigns. At the time of this report the site resolves to IP 104.21.89.127 and holds a valid Let’s Encrypt SSL certificate, giving it an appearance of legitimacy. Surprisingly, VirusTotal shows 1 out of 95 security engines detecting the threat, underscoring how rapidly these pages circumvent traditional defenses and remain undetected. Although not yet listed on major threat intelligence feeds, early network telemetry suggests the campaign is already circulating via unsolicited social-media advertisements and spoofed order-confirmation emails.
If you visited buyonek.com at any time, immediately stop using any credentials you may have entered and revoke them on the legitimate sites. Review bank and credit-card statements for unauthorized transactions and consider placing a fraud alert or credit freeze. Report the domain to your browser vendor and local anti-fraud center, then run a full scan with an updated endpoint-security tool to detect any residual malware. Bookmark only trusted retailer URLs rather than clicking ads or links to avoid similar traps in the future.
Record della segnalazione inviata
Istantanea delle prove inviate
- Inviato
- Voci del registro
- 1
- ID del caso
PD-20260503-C409A4- Titolo della pagina acquisita
- Buyone - 로그인
- Artefatto PDF
- Prova in PDF
Testo completo delle prove
Policy Violations: “Services may be used only for lawful purposes… fraud, abuse and illegal activity prohibited. Violations may result in immediate suspension.” + dedicated abuse handling and takedown
Applicable Laws: Crimes Ordinance Cap.200 (Fraud), Theft Ordinance Cap.210 §16A (fraud by deception), Personal Data (Privacy) Ordinance Cap.486
Informazioni sulla sicurezza di rete Registrar context
Pipeline di risposta alle minacce
Copertura delle blocklist
10 fonti · sincronizzato il 09/08/2026
Prove dell’esito memorizzate
Esito e attribuzione della rimozione
- Esito
live_content- Causa
content_served- Attendibilità
- 90%
Cronologia del rilevamento
Osservazioni memorizzate in ordine cronologico.
-
Disponibilità
Disponibilità: osservato per la prima volta come unknown
993d00c35140 -
Disponibilità
Disponibilità: unknown → live_content
76531947435c -
Disponibilità
Disponibilità: live_content → unknown
71dbba7d7cfa -
Disponibilità
Disponibilità: unknown → live_content
69c4b9d6873e -
Disponibilità
Disponibilità: live_content → unknown
7cebcfd4071c -
Disponibilità
Disponibilità: unknown → live_content
a2326f963ed8 -
Disponibilità
Disponibilità: live_content → unknown
ca255b61650a -
Disponibilità
Disponibilità: unknown → live_content
307ea256c67c -
Disponibilità
Disponibilità: live_content → unknown
d8f7d37d7f95 -
Disponibilità
Disponibilità: unknown → live_content
d5de160c29c9
Acquisizione salvata
Analisi dei domini
Dettagli tecniciDNS, SAN SSL, timestamp
ICANN OVERSIGHT
Accreditamento e contesto RAA
Accreditamento e contesto RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Tecnologie
3 tecnologie identificate con alta affidabilità
Analisi di VirusTotal
Analisi delle prestazioni del sito
Google PageSpeed Insights — mobile performance audit of buyonek.com · checked May 3, 2026
Questo sito ti ha influenzato in qualche modo?
Se hai inserito credenziali dell'account, informazioni personali o di pagamento oppure hai scaricato un file da questo dominio, agisci immediatamente. Di seguito sono riportate le risorse per aiutarti a segnalare l'incidente e proteggerti.
Segnalalo alle autorità locali
Seleziona il tuo Paese per ottenere contatti ufficiali del crimine informatico o creare una bozza di reclamo →.
Verifica qualsiasi dominio
Analisi delle minacce utilizzando blocklist archiviate, WHOIS, DNS e prove di scansione pubblica
Scansiona oraSegnala un tentativo di phishing
Segnala i domini sospetti al nostro database delle minacce — proteggi la comunità
SegnalaFeed in tempo reale sulle minacce
Segnalazioni recenti di phishing e modifiche osservate della disponibilità
MonitoraRimani informato, rimani al sicuro
Controlla le minacce in tempo reale oppure contesta questa segnalazione se ritieni che si tratti di un falso positivo