Why this matters — ICANN RAA §3.18 obligation & victim-assistance
On PhishDestroy delivered an evidence-backed abuse report
(repeated 2 times, most recently ) to abuse@omegatech.sc with VirusTotal detections, urlscan capture, legal violations, and full screenshot evidence.
More than 2 days later, the phishing infrastructure remains reachable
.
Under ICANN RAA §3.18 accredited registrars are contractually obliged to “take reasonable and prompt steps to investigate and respond appropriately to any reports of abuse.” Silence beyond 24 hours after a documented notification with verifiable evidence is not a timing issue — it is a policy decision to let the operation continue. PhishDestroy\'s position: where a registrar fails to act on clear evidence, the registrar has aligned itself with the operator of the scheme and bears co-responsibility for downstream harm caused to victims from the moment of notification onward.
Victim-assistance obligation. If NICENIC INTERNATIONAL GROUP CO., LIMITED doesn't consider the listed detections enough proof — that is interesting in itself, given the volume of independent vendor confirmations. But after 2 separate notifications over 2 days, with the operation still active, the registrar took no measurable action to mitigate the harm caused by their client. The reasonable next step is direct help to any identified victims — contact & payment-trail disclosure, abuse-thread transcripts, registrant data preservation — since the registrar chose, by inaction, to extend the window of damage.
epluswallet[.]com
epluswallet.com のフィッシング・安全性チェック
“Eplus wallet”
epluswallet.com:VirusTotal の 91 エンジン中 5 件が検出。DNS、SSL、レジストラ、ブロックリスト、脅威情報を確認できます。
元のフォレンジック記録を保持するため、下の PhishDestroy AI 詳細分析は英語のままです。
PhishDestroy first recorded epluswallet.com on Jul 30, 2026. This English evidence brief is rebuilt from the current structured observations stored for the report. The current evidence score, computed from those stored observations, is 81/100.
The latest stored availability state is “最後に確認されたアクティブな状態” (HTTP 200) on Aug 2, 2026 at 00:17 UTC. This is a reachability snapshot, not proof of the cause of any outage, restriction, or status change.
VirusTotal returned 5 detections from 91 scanners in the stored check on Aug 1, 2026 at 04:10 UTC. The independent blocklist snapshot recorded 2 matches (MetaMask, SEAL) across 10 configured external sources on Aug 2, 2026 at 00:20 UTC. PhishDestroy's own listing is excluded from that count.
Other stored evidence. Google Safe Browsing stored no positive flag on Jul 30, 2026 at 22:30 UTC. This time-bound result is not evidence of safety. AlienVault OTX stored 0 pulse references on Jul 30, 2026 at 22:31 UTC. OTX pulses are community-intelligence references, not vendor verdicts. Spamhaus DBL stored the result DBL_PHISH on Jul 31, 2026 at 00:30 UTC. A URLScan capture is stored from Jul 30, 2026 at 22:29 UTC.
Stored context lists registrar NICENIC INTERNATIONAL GROUP CO., LIMITED, IP address 91.92.241.159, registration date Apr 10, 2026, apparent target Across. Except for the registration date, these fields do not share a source timestamp in this report and may change.
Treat these as stored, time-bound observations rather than a live safety guarantee. Source verdicts and reachability can change, and zero or missing vendor matches never prove that a domain is safe. Avoid interacting with the domain while uncertainty remains, and use the appeal process if this report is inaccurate.
ネットワークセキュリティインテリジェンス Registrar Integrity Alert
脅威対応 Pipeline
公開ブロックリスト登録状況
証拠の収集
ドメイン・インテリジェンス
技術的な詳細DNS、SSL SAN、タイムスタンプ
ICANN OVERSIGHT
Accreditation and RAA context
Accreditation and RAA context
ICANNには支払いが済んだ。説明責任は届かなかった。
このgTLDでは、上記のレジストラはICANNとの契約に基づいて運営されています。ICANNは、登録、更新、移管に連動する年間手数料、変動手数料、および取引ベースの手数料を徴収します。
認定:収益化済み。説明責任:後ほどもう一度ご確認ください。
そして魔法が始まります。ICANNがRAA §3.18を書き、レジストラは自らの顧客基盤内の不正利用を自ら調査し、被害者は証拠を無償で提供する一方、各層は誰か別の者が動くのを待ちます。それで被害者が少しでも安全になった気がするなら、結構なことです――請求書は仕事を果たしたわけです。
使用技術 · 10 identified
WordPress is a free and open-source content management system written in PHP and paired with a MySQL or MariaDB database. Features include a plugin architecture and a template system.
wordpress.org 100% confidenceChart.js is an open-source JavaScript library that allows you to draw different types of charts by using the HTML5 canvas element.
www.chartjs.org 75% confidenceApache is a free and open-source cross-platform web server software.
httpd.apache.org 100% confidencereCAPTCHA is a free service from Google that helps protect websites from spam and abuse.
www.google.com 100% confidenceLightbox is small javascript library used to overlay images on top of the current page.
lokeshdhakar.com 100% confidenceQuery Migrate is a javascript library that allows you to preserve the compatibility of your jQuery code developed for versions of jQuery older than 1.9.
github.com 100% confidencejQuery is a JavaScript library which is a free, open-source software designed to simplify HTML DOM tree traversal and manipulation, as well as event handling, CSS animation, and Ajax.
jquery.com 100% confidenceHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100% confidenceVirusTotalによる分析
アーカイブ済み証拠
サイトパフォーマンス分析
Google PageSpeed Insights — mobile performance audit of epluswallet.com · checked Jul 30, 2026
サイト設定分析
証拠および外部報告書
このサイトによって何か影響を受けましたか?
If you entered account credentials, personal or payment information, or downloaded a file from this domain, take immediate action. Below are resources to help you report the incident and protect yourself.
お住まいの地域の当局へ報告してください
国を選択して、以下の情報を入手してください サイバー犯罪に関する公式の連絡先, or create a complaint draft →
About This Report: epluswallet.com
This report presents the latest stored evidence available to PhishDestroy. Source timestamps are shown where available; availability and vendor verdicts can change after collection.
The site displays a page titled “Eplus wallet”, which may be designed to impersonate Across.
epluswallet.com has been flagged by 5 security vendors as of August 2, 2026.
このリストが不正確であると思われる場合は、異議申し立てを提出する までご連絡ください。当社の方法論について詳しくは、よくある質問ページ をご覧ください。
任意のドメインを確認する
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
今すぐスキャンフィッシングを報告する
不審なドメインを当社の脅威データベースに報告してください — コミュニティを守りましょう
Reportリアルタイム脅威情報フィード
Recent phishing reports and observed availability changes
Monitor最新情報を入手し、安全を確保しましょう
リアルタイムの脅威を監視するか、誤検知だと思われる場合はこのリストに異議を申し立ててください
