Why this matters — ICANN RAA §3.18 obligation & victim-assistance
On PhishDestroy delivered an evidence-backed abuse report
(repeated 11 times, most recently ) to abuse@nic.at with the evidence stored for the case at that time.
More than 5 months later, the phishing infrastructure remains reachable
.
Under ICANN RAA §3.18 accredited registrars are contractually obliged to “take reasonable and prompt steps to investigate and respond appropriately to any reports of abuse.” Silence beyond 24 hours after a documented notification with verifiable evidence is not a timing issue — it is a policy decision to let the operation continue. PhishDestroy\'s position: where a registrar fails to act on clear evidence, the registrar has aligned itself with the operator of the scheme and bears co-responsibility for downstream harm caused to victims from the moment of notification onward.
Victim-assistance obligation. If TLD Registry (.at) doesn't consider the listed detections enough proof — that is interesting in itself, given the volume of independent vendor confirmations. But after 11 separate notifications over 5 months, with the operation still active, the registrar took no measurable action to mitigate the harm caused by their client. The reasonable next step is direct help to any identified victims — contact & payment-trail disclosure, abuse-thread transcripts, registrant data preservation — since the registrar chose, by inaction, to extend the window of damage.
emcas[.]at
Verifica phishing e sicurezza per emcas.at
“Emcas: Elon Musk’s Official Crypto Casino Powered by Blockchain”
emcas.at: 15 rilevamenti su 91 scanner VirusTotal. Consulta DNS, SSL, registrar, blocklist e dati sulle minacce.
L’analisi dettagliata di PhishDestroy AI resta in inglese per preservare il rapporto forense originale.
PhishDestroy first observed emcas.at on Dec 28, 2025. Evidence score: 100/100 (a triage score, not a probability).
Threat signals: 15 of 91 VirusTotal engines flagged the domain on Jul 28, 2026 at 02:23 UTC. Spamhaus DBL: DBL_PHISH on Jul 14, 2026 at 14:32 UTC.
The endpoint responded with HTTP 403 on Aug 5, 2026 at 22:14 UTC, but access was restricted; content availability remains unconfirmed.
Other observations: No external blocklist matches were recorded in the snapshot from Aug 5, 2026 at 22:20 UTC. Google Safe Browsing recorded no flag on Mar 3, 2026 at 04:14 UTC. AlienVault OTX recorded 0 community pulse references on Mar 1, 2026 at 13:41 UTC. URLScan captured the domain on Feb 24, 2026 at 01:20 UTC. Negative or missing results do not establish safety.
Context: registrar TLD Registry (.at), IP address 188.114.96.3, registration date Nov 30, 2025, apparent target Genericcrypto. Infrastructure details may have changed since collection.
This report summarizes time-bound observations, not a live guarantee. Avoid interacting with the domain; submit an appeal if the report is inaccurate.
Indicatori di sicurezza
Pipeline di risposta alle minacce
Stato della lista di blocco pubblica
Cronologia delle segnalazioni di abuso · 11 stored reports over 73 days · click to expand
-
Report #1 ICANN CC 151h still active Feb 15, 2026 · 01:23 UTCESCALATION #2 (151h active): Phishing - emcas[.]atabuse@nic.at compliance@icann.org
-
Report #2 ICANN CC 573h still active Mar 4, 2026 · 15:54 UTCESCALATION #3 (573h active): Phishing - emcas[.]atabuse@nic.at compliance@icann.org
-
Report #3 ICANN CC 616h still active Mar 6, 2026 · 10:41 UTCESCALATION #4 (616h active): Phishing - emcas[.]atabuse@nic.at compliance@icann.org
-
Report #5 ICANN CC 1100h still active Mar 26, 2026 · 18:21 UTCESCALATION #5 (1100h active): Phishing - emcas[.]atabuse@nic.at compliance@icann.org
-
Report #6 ICANN CC 1172h still active Mar 29, 2026 · 17:57 UTCESCALATION #6 (1172h active): Phishing - emcas[.]atabuse@nic.at compliance@icann.org
-
Report #7 ICANN CC 1429h still active Apr 9, 2026 · 10:56 UTCESCALATION #7 (1429h active): Phishing - emcas[.]atabuse@nic.at compliance@icann.org
-
Report #8 ICANN CC 1618h still active Apr 17, 2026 · 08:11 UTCESCALATION #8 (1618h active): Phishing - emcas[.]atabuse@nic.at compliance@icann.org
-
Report #9 ICANN CC 1752h still active Apr 22, 2026 · 22:06 UTCESCALATION #9 (1752h active): Phishing - emcas[.]atabuse@nic.at compliance@icann.org
-
Report #10 ICANN CC 1798h still active Apr 24, 2026 · 20:05 UTCESCALATION #10 (1798h active): Phishing - emcas[.]atabuse@nic.at compliance@icann.org
-
Report #11 ICANN CC 1843h still active Apr 26, 2026 · 17:13 UTCESCALATION #11 (1843h active): Phishing - emcas[.]atabuse@nic.at compliance@icann.org
-
Report #12 ICANN CC 1892h still active Apr 28, 2026 · 18:10 UTCESCALATION #12 (1892h active): Phishing - emcas[.]atabuse@nic.at compliance@icann.org
Analisi di VirusTotal
Prove archiviate
Analisi delle prestazioni del sito
Google PageSpeed Insights — mobile performance audit of emcas.at · checked Mar 1, 2026
Dati e relazioni esterne
“The website emcas.at is a fraudulent crypto-gambling platform operating an 'Advance-Fee Scam' (419 scam). The site lures users with fake balances (e.g., $3,405.20) and then demands an upfront deposit of $25 or more in Bitcoin (wallet: bc1q8hfcwes970y6mlqpwhng40w5e0qlckd) to 'unlock' or 'verify' the account for withdrawal. The platform uses stolen corporate credentials (impersonating TechSolutions Group N.V.) and lacks any valid gaming license. When challenged with legal inquiries, the support te”
Questo sito ti ha influenzato in qualche modo?
Se hai inserito credenziali dell'account, informazioni personali o di pagamento oppure hai scaricato un file da questo dominio, agisci immediatamente. Di seguito sono riportate le risorse per aiutarti a segnalare l'incidente e proteggerti.
Segnalalo alle autorità locali
Seleziona il tuo Paese per ottenere contatti ufficiali del crimine informatico o creare una bozza di reclamo →.
Informazioni su questo rapporto: emcas.at
Questo rapporto presenta le ultime prove archiviate disponibili per PhishDestroy. I timestamp della sorgente vengono mostrati ove disponibili; la disponibilità e i verdetti del fornitore possono cambiare dopo il ritiro.
Il sito catturato mostrava il titolo della pagina “Emcas: Elon Musk’s Official Crypto Casino Powered by Blockchain” e potrebbe spacciarsi per Genericcrypto.
Al momento di 05/08/2026, emcas.at ha ricevuto rilevamenti dai motori di sicurezza 15.
Se ritieni che questo elenco sia impreciso, presentare ricorso. Per conoscere la nostra metodologia, visita Pagina delle domande frequenti.
Verifica qualsiasi dominio
Analisi delle minacce utilizzando blocklist archiviate, WHOIS, DNS e prove di scansione pubblica
Scansiona oraSegnala un tentativo di phishing
Segnala i domini sospetti al nostro database delle minacce — proteggi la comunità
SegnalaFeed in tempo reale sulle minacce
Segnalazioni recenti di phishing e modifiche osservate della disponibilità
MonitoraRimani informato, rimani al sicuro
Controlla le minacce in tempo reale oppure contesta questa segnalazione se ritieni che si tratti di un falso positivo