Why this matters — ICANN RAA §3.18 obligation & victim-assistance
On PhishDestroy delivered an evidence-backed abuse report
(repeated 5 times, most recently ) to domainabuse@service.aliyun.com with the evidence stored for the case at that time.
More than 6 months later, the phishing infrastructure remains reachable
.
Under ICANN RAA §3.18 accredited registrars are contractually obliged to “take reasonable and prompt steps to investigate and respond appropriately to any reports of abuse.” Silence beyond 24 hours after a documented notification with verifiable evidence is not a timing issue — it is a policy decision to let the operation continue. PhishDestroy\'s position: where a registrar fails to act on clear evidence, the registrar has aligned itself with the operator of the scheme and bears co-responsibility for downstream harm caused to victims from the moment of notification onward.
Victim-assistance obligation. If Dominet (HK) Limited doesn't consider the listed detections enough proof — that is interesting in itself, given the volume of independent vendor confirmations. But after 5 separate notifications over 6 months, with the operation still active, the registrar took no measurable action to mitigate the harm caused by their client. The reasonable next step is direct help to any identified victims — contact & payment-trail disclosure, abuse-thread transcripts, registrant data preservation — since the registrar chose, by inaction, to extend the window of damage.
elongamb[.]com
elongamb.com のフィッシング・安全性チェック
“Elongamb: Elon Musk’s Official Crypto Casino Powered by Blockchain”
elongamb.com — クローク済み · 到達可能 (HTTP 666). ブランドの偽装: Genericcrypto; 詐欺タイプ: Crypto Scam. 証拠の概要: VT 17/93 (ADMINUSLabs, alphaMountain.ai, BitDefender, CRDF, CyRadar); URLQuery 2 alerts; URLScan malicious; GSB no flag; Spamhaus DBL_PHISH; BL 2 (MetaMask, SEAL); PD 100/100. レジストラ: Dominet (HK).
元のフォレンジック記録を保持するため、下の PhishDestroy AI 詳細分析は英語のままです。
PhishDestroy first observed elongamb.com on Jan 31, 2026. Stored content metadata identifies Genericcrypto as the apparent target. The captured page title is “Elongamb: Elon Musk’s Official Crypto Casino Powered by Blockchain”. Stored page analysis classifies the content as crypto scam. Campaign clustering links the hostname to the Gambler Scam kit. Current evidence score: 100/100 (critical).
Positive findings are stored from 6 sources: VirusTotal, MetaMask, SEAL, Spamhaus DBL, URLQuery, and URLScan. VirusTotal recorded 17 detections among 93 engines: ADMINUSLabs, alphaMountain.ai, BitDefender, CRDF, CyRadar, ESET, Forcepoint ThreatSeeker, Fortinet, G-Data, Gridinsoft, Kaspersky, Lionic, Netcraft, Seclookup, SOCRadar, Sophos, VIPRE on Jul 18, 2026 at 14:45 UTC. MetaMask and SEAL listed the hostname in the external-blocklist snapshot on Aug 7, 2026 at 22:20 UTC. Spamhaus DBL: DBL_PHISH on Jul 14, 2026 at 10:36 UTC. URLQuery recorded 2 threat-system alerts on Feb 1, 2026 at 15:41 UTC. URLScan returned a malicious verdict with score 100; scan metadata assigned phishing as its category on Jul 29, 2026 at 03:26 UTC. Non-positive and contextual checks: Gridinsoft assigned a trust score of 1/100 (Suspicious); no observation timestamp was retained. ScamAdviser assigned a trust score of 1/100 (Very Likely Unsafe); no observation timestamp was retained. AlienVault OTX listed 1 community pulse reference (not vendor detections) on Mar 1, 2026 at 10:36 UTC. Google Safe Browsing returned no flag on Mar 3, 2026 at 04:14 UTC. PhishStats returned no feed match on Mar 2, 2026 at 00:04 UTC.
Cloaking was recorded with HTTP 666 on Aug 7, 2026 at 22:14 UTC. Registration records for the domain list Dominet (HK) Limited as the registrar. At collection time, the hostname resolved to 69.5.189.55 on AS42624 (swissnetwork02 Global-Data System IT Corporation, SC). The recorded endpoint location is Zürich, CH. The stored server header is openresty-cast. DOM analysis on Jul 28, 2026 at 02:20 UTC returned 0/100; the source detections above were recorded separately. The evidence archive retains 3 visual captures from PhishDestroy, URLScan, and URLQuery. TLS metadata lists Internet Widgits Pty Ltd as the certificate issuer with validity through Dec 25, 2033; checked Mar 15, 2026 at 05:55 UTC.
The content indicators and 6 positive source findings support the current Genericcrypto-themed crypto scam classification.
セキュリティシグナル
ネットワークセキュリティインテリジェンス
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Hagezi Threat Feed | elongamb.com |
malicious | Sinkholed |
| DNS4EU | elongamb.com |
malicious | Sinkholed |
脅威対応 Pipeline
公開ブロックリスト登録状況
保存済みキャプチャ
ドメイン・インテリジェンス
技術的な詳細DNS、SSL SAN、タイムスタンプ
ICANN OVERSIGHT
認定と RAA の背景
認定と RAA の背景
ICANNには支払いが済んだ。説明責任は届かなかった。
このgTLDでは、上記のレジストラはICANNとの契約に基づいて運営されています。ICANNは、登録、更新、移管に連動する年間手数料、変動手数料、および取引ベースの手数料を徴収します。
認定:収益化済み。説明責任:後ほどもう一度ご確認ください。
そして魔法が始まります。ICANNがRAA §3.18を書き、レジストラは自らの顧客基盤内の不正利用を自ら調査し、被害者は証拠を無償で提供する一方、各層は誰か別の者が動くのを待ちます。それで被害者が少しでも安全になった気がするなら、結構なことです――請求書は仕事を果たしたわけです。
不正利用報告履歴 · 5 stored reports over 123 days · click to expand
-
Report #1 Jan 31, 2026 · 20:11 UTCPhishing Abuse Report: elongamb[.]comdomainabuse@service.aliyun.com
-
Report #2 Escalation 190h still active Feb 8, 2026 · 18:23 UTCESCALATION #2 (190h active): Phishing - elongamb[.]comdomainabuse@service.aliyun.com
-
Report #3 ICANN CC 1515h still active Apr 5, 2026 · 02:16 UTCESCALATION #3 (1515h active): Phishing - elongamb[.]comdomainabuse@service.aliyun.com abuse@verisign-grs.com compliance@icann.org
-
Report #4 ICANN CC 2242h still active May 5, 2026 · 09:40 UTCESCALATION #4 (2242h active): Phishing - elongamb[.]comdomainabuse@service.aliyun.com abuse@verisign-grs.com compliance@icann.org
-
Report #5 ICANN CC 2905h still active Jun 2, 2026 · 22:50 UTCESCALATION #5 (2905h active): Phishing - elongamb[.]comdomainabuse@service.aliyun.com abuse@verisign-grs.com compliance@icann.org
VirusTotalによる分析
アーカイブ済み証拠
証拠および外部報告書
このサイトによって何か影響を受けましたか?
アカウント資格情報、個人情報、支払い情報を入力した場合、またはこのドメインからファイルをダウンロードした場合は、すぐに対処してください。インシデントを報告し、自分自身を守るのに役立つリソースを以下に示します。
お住まいの地域の当局へ報告してください
サイバー犯罪の公式連絡先 または 苦情草稿を作成する → を取得するには、国を選択してください。
任意のドメインを確認する
保存されたブロックリスト、WHOIS、DNS、および公開スキャン証拠を使用した脅威分析
今すぐスキャンフィッシングを報告する
不審なドメインを当社の脅威データベースに報告してください — コミュニティを守りましょう
レポートリアルタイム脅威情報フィード
最近のフィッシングレポートと観察された可用性の変化
監視最新情報を入手し、安全を確保しましょう
リアルタイムの脅威を監視するか、誤検知だと思われる場合はこのリストに異議を申し立ててください