Why this matters — ICANN RAA §3.18 obligation & victim-assistance
On PhishDestroy delivered an evidence-backed abuse report
(repeated 3 times, most recently ) to abuse@dynadot.com with the evidence stored for the case at that time.
More than 4 months later, the phishing infrastructure remains reachable
.
Under ICANN RAA §3.18 accredited registrars are contractually obliged to “take reasonable and prompt steps to investigate and respond appropriately to any reports of abuse.” Silence beyond 24 hours after a documented notification with verifiable evidence is not a timing issue — it is a policy decision to let the operation continue. PhishDestroy\'s position: where a registrar fails to act on clear evidence, the registrar has aligned itself with the operator of the scheme and bears co-responsibility for downstream harm caused to victims from the moment of notification onward.
Victim-assistance obligation. If Dynadot Inc doesn't consider the listed detections enough proof — that is interesting in itself, given the volume of independent vendor confirmations. But after 3 separate notifications over 4 months, with the operation still active, the registrar took no measurable action to mitigate the harm caused by their client. The reasonable next step is direct help to any identified victims — contact & payment-trail disclosure, abuse-thread transcripts, registrant data preservation — since the registrar chose, by inaction, to extend the window of damage.
hydradragon[.]com
hydradragon.com のフィッシング・安全性チェック
“Steal A Brainrot”
hydradragon.com — クローク済み · 到達可能 (HTTP 403). 詐欺タイプ: Generic Phishing. 証拠の概要: VT 5/91 (alphaMountain.ai, CRDF, Forcepoint ThreatSeeker, Gridinsoft, SOCRadar); URLQuery 0; URLScan no malicious verdict; GSB no flag; BL 0; cloaking observed; PD 71/100. レジストラ: Dynadot.
元のフォレンジック記録を保持するため、下の PhishDestroy AI 詳細分析は英語のままです。
hydradragon.com entered the PhishDestroy evidence set on Apr 6, 2026. The stored content classification is generic phishing. The assembled evidence scores 71/100 (high).
One independent source is positive: VirusTotal. VirusTotal recorded 5 detections among 91 engines: alphaMountain.ai, CRDF, Forcepoint ThreatSeeker, Gridinsoft, SOCRadar on Jul 28, 2026 at 02:51 UTC. The evidence is not unanimous. The external blocklist snapshot contained no matches on Aug 7, 2026 at 14:20 UTC. URLQuery recorded no positive detection. On Apr 6, 2026 at 16:00 UTC, Google Safe Browsing returned no flag; PhishStats returned no feed match. URLScan completed without a malicious verdict (score 0).
Cloaking was recorded with HTTP 403 on Aug 7, 2026 at 10:17 UTC. Registration records for the domain list Dynadot Inc as the registrar and Apr 6, 2026 as the creation date. Registration preceded first observation by 0 days. At collection time, the hostname resolved to 35.208.103.74 on AS15169 (Google LLC). The associated network metadata labels the endpoint as Google Cloud (us-central1) in Council Bluffs, US. The stored server header is nginx. Captured page title: “Steal A Brainrot”. The evidence archive retains 2 visual captures from PhishDestroy and URLScan. IoC extraction completed on Jul 29, 2026 at 02:07 UTC; stored 0 format-validated wallet addresses and 0 Telegram indicators. TLS metadata lists Let's Encrypt as the certificate issuer with validity through Jun 29, 2026; checked Apr 23, 2026 at 05:00 UTC.
No target brand has been confirmed from stored page content; hostname wording alone is not treated as brand evidence.
脅威対応 Pipeline
公開ブロックリスト登録状況
保存済みキャプチャ
ドメイン・インテリジェンス
技術的な詳細DNS、SSL SAN、タイムスタンプ
ICANN OVERSIGHT
認定と RAA の背景
認定と RAA の背景
ICANNには支払いが済んだ。説明責任は届かなかった。
このgTLDでは、上記のレジストラはICANNとの契約に基づいて運営されています。ICANNは、登録、更新、移管に連動する年間手数料、変動手数料、および取引ベースの手数料を徴収します。
認定:収益化済み。説明責任:後ほどもう一度ご確認ください。
そして魔法が始まります。ICANNがRAA §3.18を書き、レジストラは自らの顧客基盤内の不正利用を自ら調査し、被害者は証拠を無償で提供する一方、各層は誰か別の者が動くのを待ちます。それで被害者が少しでも安全になった気がするなら、結構なことです――請求書は仕事を果たしたわけです。
不正利用報告履歴 · 3 stored reports over 101 days · click to expand
-
Report #2 ICANN CC 198h still active Apr 15, 2026 · 03:14 UTCESCALATION #2 (198h active): Phishing - hydradragon[.]comabuse@dynadot.com abuse@verisign-grs.com compliance@icann.org
-
Report #3 ICANN CC 284h still active Apr 18, 2026 · 17:16 UTCESCALATION #3 (284h active): Phishing - hydradragon[.]comabuse@dynadot.com abuse@verisign-grs.com compliance@icann.org
-
Report #4 ICANN CC 2610h still active Jul 24, 2026 · 15:00 UTCESCALATION #4 (2610h active): Phishing - hydradragon[.]comabuse@dynadot.com abuse@verisign-grs.com compliance@icann.org
VirusTotalによる分析
アーカイブ済み証拠
サイトパフォーマンス分析
Google PageSpeed Insights — mobile performance audit of hydradragon.com · checked Apr 6, 2026
証拠および外部報告書
このサイトによって何か影響を受けましたか?
アカウント資格情報、個人情報、支払い情報を入力した場合、またはこのドメインからファイルをダウンロードした場合は、すぐに対処してください。インシデントを報告し、自分自身を守るのに役立つリソースを以下に示します。
お住まいの地域の当局へ報告してください
サイバー犯罪の公式連絡先 または 苦情草稿を作成する → を取得するには、国を選択してください。
任意のドメインを確認する
保存されたブロックリスト、WHOIS、DNS、および公開スキャン証拠を使用した脅威分析
今すぐスキャンフィッシングを報告する
不審なドメインを当社の脅威データベースに報告してください — コミュニティを守りましょう
レポートリアルタイム脅威情報フィード
最近のフィッシングレポートと観察された可用性の変化
監視最新情報を入手し、安全を確保しましょう
リアルタイムの脅威を監視するか、誤検知だと思われる場合はこのリストに異議を申し立ててください