MALICIOUS — CRITICAL
portflowltd[.]com
portflowltd.com is currently listed as a high‑risk generic phishing site.
- VirusTotal
- 6/91
- Blocklists
- No stored match
- Disponibilità
- Ultimo attivo conosciuto · HTTP 200
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Notification and current-status evidence
The sent-report ledger records the first outgoing report at .
The recorded recipient is abuse@whiteprivacy.com.
The latest stored availability evidence still shows the domain reachable; 2 months has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
Jump to section
portflowltd.com — Ultimo attivo conosciuto (HTTP 200). Tipo di truffa: Generic Phishing. Riepilogo delle prove: VirusTotal 6/91 (alphaMountain.ai, CRDF, Forcepoint ThreatSeeker, Fortinet, Gridinsoft); Spamhaus DBL_SPAM; PhishDestroy score 80/100. Registrar: TuringSign.
L’analisi dettagliata di PhishDestroy AI resta in inglese per preservare il rapporto forense originale.
Evidence Analysis
portflowltd.com is currently listed as a high‑risk generic phishing site. The domain was created on 7 April 2025 and remains active as of the 12 July 2026 reporting date. Automated analysis classifies the site under the generic_phishing category, and it appears on one public blocklist maintained by PhishDestroy. Six of ninety‑five VirusTotal scanners have flagged the host, indicating a modest but notable detection rate among security vendors. The domain resolves to the IPv4 address 163.61.188.7, which resolves to a server located in the United States, specifically the MIT network segment. Registration was performed through TuringSign Inc. d/b/a Cosmotown, and the authoritative name servers are dns1.lytehosting.com through dns4.lytehosting.com. The site serves a valid Let’s Encrypt R12 TLS certificate and returns HTTP 200 responses. A review of the page source reveals the presence of Zoho, Bootstrap, LiteSpeed, OWL Carousel, jQuery, Google Tag Manager, Popper, and HTTP/3, indicating a modern web stack that may be leveraged to increase credibility. The visible page title reads “HOME | PORTFLOW SERVICES LTD,” a clear attempt to mimic a legitimate corporate brand. Gridinsoft’s trust scoring system assigns a rating of 26 out of 100, reflecting a low confidence level in the site’s legitimacy. Although only a single blocklist entry is currently recorded, the combination of the phishing classification, the modest vendor detection count, and the low trust score collectively support the high‑risk rating. Defenders should add portflowltd.com and its resolving IP address 163.61.188.7 to network‑level deny lists and monitor DNS queries for the associated name servers. Email gateways ought to enforce URL filtering against known phishing indicators, and any credential‑capture forms observed on the site should be treated as malicious. Continuous re‑evaluation is advised, as changes to the hosting infrastructure or additional vendor detections could alter the threat posture.
Copertura dei dati14 recorded checks
Indicatori di sicurezza
Pipeline di risposta alle minacce
Stato della lista di blocco pubblica
Acquisizione salvata
Analisi dei domini
Dettagli tecniciDNS, SAN SSL, timestamp
ICANN OVERSIGHT
Accreditamento e contesto RAA
Accreditamento e contesto RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Tecnologie · 8 identified
Bootstrap is a free and open-source CSS framework directed at responsive, mobile-first front-end web development. It contains CSS and JavaScript-based design templates for typography, forms, buttons, navigation, and other interface components.
getbootstrap.com Confidenza al 100%OWL Carousel is an enabled jQuery plugin that lets you create responsive carousel sliders.
owlcarousel2.github.io Confidenza al 100%jQuery is a JavaScript library which is a free, open-source software designed to simplify HTML DOM tree traversal and manipulation, as well as event handling, CSS animation, and Ajax.
jquery.com Confidenza al 100%Google Tag Manager is a tag management system (TMS) that allows you to quickly and easily update measurement codes and related code fragments collectively known as tags on your website or mobile app.
www.google.com Confidenza al 100%Popper is a positioning engine, its purpose is to calculate the position of an element to make it possible to position it near a given reference element.
popper.js.org Confidenza al 100%HTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org Confidenza al 100%Analisi di VirusTotal
Analisi delle prestazioni del sito
Google PageSpeed Insights — mobile performance audit of portflowltd.com · checked May 20, 2026
Dati e relazioni esterneIndependent lookups and source reports
PD-20260520-05DA50 Recipient: abuse@whiteprivacy.com Victim safety and official reportingImmediate actions and verified reporting channels
Se hai inserito credenziali dell'account, informazioni personali o di pagamento oppure hai scaricato un file da questo dominio, agisci immediatamente. Di seguito sono riportate le risorse per aiutarti a segnalare l'incidente e proteggerti.
Segnalalo alle autorità locali
Seleziona il tuo Paese per ottenere contatti ufficiali del crimine informatico o creare una bozza di reclamo →.