driftprotocolscompliance[.]info
証拠の概要
The domain driftprotocolscompliance.info has been identified as a brand impersonation threat targeting Drift, a known decentralized finance platform. Analysis confirms the domain was designed to mimic legitimate Drift services, likely to deceive users into disclosing sensitive information or interacting with malicious infrastructure. The domain is currently offline, but prior activity indicates a deliberate attempt to exploit trust in the Drift brand. Technical indicators reveal the domain was registered through NICENIC INTERNATIONAL GROUP CO., LIMITED on May 26, 2026, an unusually future-dated creation that may suggest evasion tactics. It resolved to the IP address 104.21.68.61 and employed infrastructure protected by Cloudflare, including HTTP/3 and HSTS protocols, which are often leveraged to obscure malicious activity. Security vendors flagged the domain in 9 of 95 VirusTotal scans, while Gridinsoft assigned a trust score of 0/100. The domain also appears on one security blocklist, and its page title, 'Just a moment...,' aligns with patterns observed in transient phishing deployments. Current status confirms driftprotocolscompliance.info is offline, reducing immediate risk to users. However, the domain's infrastructure and registration details suggest potential for reactivation or reuse in future campaigns. Organizations and individuals are advised to proactively block the domain and its associated IP address (104.21.68.61) at the network level. Users who may have interacted with the domain should verify account integrity, particularly for Drift-related services, and monitor for unauthorized transactions or access attempts. Security teams should treat domains registered through NICENIC INTERNATIONAL GROUP CO., LIMITED with heightened scrutiny, given its association with this and similar threats.
送信済み証拠のスナップショット
- 送信日時
- 台帳レコード
- 1
- ケース ID
PD-20260531-4DCB23- 取得ページのタイトル
- Just a moment...
- PDF 資料
- 証拠 PDF
証拠全文
Acceptable Use Policy (AUP): The domain driftprotocolscompliance.info is engaged in phishing activities, which directly contravenes your AUP prohibiting illegal activities, fraud, and deception.
Terms of Service (TOS): The registrar reserves the right to suspend or terminate services for violations. The ongoing use of this domain for phishing warrants immediate action under your TOS.
Applicable Laws (Unknown):
Computer Fraud and Abuse Act (CFAA): This U.S. federal law prohibits unauthorized access to computer systems and fraud, which is applicable to phishing schemes.
Wire Fraud Statute (18 U.S.C. § 1343): Engaging in schemes to defraud individuals through electronic communications constitutes wire fraud, applicable to the activities associated with this domain.
CAN-SPAM Act (15 U.S.C. § 7701): This law regulates commercial email and prohibits misleading headers and deceptive subject lines, which are often utilized in phishing attempts.
Regulatory Note: Failure to act on this report may expose your organization to liability under applicable laws and regulatory frameworks. Immediate suspension of the domain is recommended to mitigate potential legal repercussions.
Data Coverage
ネットワークセキュリティインテリジェンス
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| YARAhub by abuse.ch | driftprotocolscompliance.info/favicon.ico |
malware | Detects file containing Telegram Bot API |
| DNS4EU | driftprotocolscompliance.info |
malicious | Sinkholed |
脅威対応 Pipeline
ブロックリストの確認範囲
監視対象の外部情報源 10 件 · 保存スナップショット 2026年8月12日
検出タイムライン
-
VirusTotal
2 → 9
保存済みキャプチャ
ドメイン・インテリジェンス
技術詳細DNS、TLS 名、タイムスタンプ
ICANN OVERSIGHT
認定と RAA の背景
認定と RAA の背景
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
使用技術
高確信度で特定された技術:3 件
VirusTotalによる分析
サイトパフォーマンス分析
Google PageSpeed Insights — mobile performance audit of driftprotocolscompliance.info · checked Jun 26, 2026
このサイトによって何か影響を受けましたか?
アカウント資格情報、個人情報、支払い情報を入力した場合、またはこのドメインからファイルをダウンロードした場合は、すぐに対処してください。インシデントを報告し、自分自身を守るのに役立つリソースを以下に示します。
お住まいの地域の当局へ報告してください
サイバー犯罪の公式連絡先 または 苦情草稿を作成する → を取得するには、国を選択してください。
任意のドメインを確認する
保存されたブロックリスト、WHOIS、DNS、および公開スキャン証拠を使用した脅威分析
今すぐスキャンフィッシングを報告する
不審なドメインを当社の脅威データベースに報告してください — コミュニティを守りましょう
レポートリアルタイム脅威情報フィード
最近のフィッシングレポートと観察された可用性の変化
監視最新情報を入手し、安全を確保しましょう
リアルタイムの脅威を監視するか、誤検知だと思われる場合はこのリストに異議を申し立ててください