Why this matters — ICANN RAA §3.18 obligation & victim-assistance
On PhishDestroy delivered an evidence-backed abuse report
(repeated 4 times, most recently ) to abuse@squarespace.com with the evidence stored for the case at that time.
More than 6 months later, the phishing infrastructure remains reachable
.
Under ICANN RAA §3.18 accredited registrars are contractually obliged to “take reasonable and prompt steps to investigate and respond appropriately to any reports of abuse.” Silence beyond 24 hours after a documented notification with verifiable evidence is not a timing issue — it is a policy decision to let the operation continue. PhishDestroy\'s position: where a registrar fails to act on clear evidence, the registrar has aligned itself with the operator of the scheme and bears co-responsibility for downstream harm caused to victims from the moment of notification onward.
Victim-assistance obligation. If Squarespace Domains II LLC. doesn't consider the listed detections enough proof — that is interesting in itself, given the volume of independent vendor confirmations. But after 4 separate notifications over 6 months, with the operation still active, the registrar took no measurable action to mitigate the harm caused by their client. The reasonable next step is direct help to any identified victims — contact & payment-trail disclosure, abuse-thread transcripts, registrant data preservation — since the registrar chose, by inaction, to extend the window of damage.
multiscan[.]app
multiscan.app のフィッシング・安全性チェック
“AMLBot - Comprehensive AML Compliance Solutions for Crypto”
multiscan.app:VirusTotal の 91 エンジン中 15 件が検出。DNS、SSL、レジストラ、ブロックリスト、脅威情報を確認できます。
元のフォレンジック記録を保持するため、下の PhishDestroy AI 詳細分析は英語のままです。
PhishDestroy first observed multiscan.app on Feb 26, 2026. Evidence score: 100/100 (a triage score, not a probability).
Threat signals: 15 of 91 VirusTotal engines flagged the domain on Aug 5, 2026 at 14:14 UTC. AlienVault OTX recorded 1 community pulse reference on Mar 1, 2026 at 00:11 UTC. Spamhaus DBL: DBL_PHISH on Jul 14, 2026 at 02:34 UTC.
The latest probe reached the domain (HTTP 200) on Aug 5, 2026 at 22:27 UTC. Reachability alone does not establish whether the content is safe.
Other observations: No external blocklist matches were recorded in the snapshot from Aug 6, 2026 at 02:20 UTC. Google Safe Browsing recorded no flag on Mar 2, 2026 at 20:57 UTC. URLScan captured the domain on Mar 25, 2026 at 11:38 UTC. Negative or missing results do not establish safety.
Context: registrar Squarespace Domains II LLC., IP address 108.61.166.34, registration date Feb 21, 2026, apparent target AMLBot. Infrastructure details may have changed since collection.
This report summarizes time-bound observations, not a live guarantee. Avoid interacting with the domain; submit an appeal if the report is inaccurate.
脅威対応 Pipeline
公開ブロックリスト登録状況
保存済みキャプチャ
ドメイン・インテリジェンス
技術的な詳細DNS、SSL SAN、タイムスタンプ
ICANN OVERSIGHT
認定と RAA の背景
認定と RAA の背景
ICANNには支払いが済んだ。説明責任は届かなかった。
このgTLDでは、上記のレジストラはICANNとの契約に基づいて運営されています。ICANNは、登録、更新、移管に連動する年間手数料、変動手数料、および取引ベースの手数料を徴収します。
認定:収益化済み。説明責任:後ほどもう一度ご確認ください。
そして魔法が始まります。ICANNがRAA §3.18を書き、レジストラは自らの顧客基盤内の不正利用を自ら調査し、被害者は証拠を無償で提供する一方、各層は誰か別の者が動くのを待ちます。それで被害者が少しでも安全になった気がするなら、結構なことです――請求書は仕事を果たしたわけです。
不正利用報告履歴 · 4 stored reports over 115 days · click to expand
-
Report #1 Escalation 181h still active Feb 6, 2026 · 23:11 UTCESCALATION #2 (181h active): Phishing - multiscan[.]appabuse-complaints@squarespace.com
-
Report #2 Escalation 47h still active Feb 9, 2026 · 02:03 UTCESCALATION #3 (47h active): Phishing - multiscan[.]appabuse-complaints@squarespace.com
-
Report #3 ICANN CC 292h still active Feb 19, 2026 · 06:40 UTCESCALATION #4 (292h active): Phishing - multiscan[.]appabuse@squarespace.com registry-abuse-support@google.com compliance@icann.org
-
Report #5 ICANN CC 2733h still active Jun 1, 2026 · 02:14 UTCESCALATION #5 (2733h active): Phishing - multiscan[.]appabuse@squarespace.com registry-abuse-support@google.com compliance@icann.org
使用技術 · 1 identified
High-performance HTTP server and reverse proxy, known for stability and low resource usage.
VirusTotalによる分析
サイトパフォーマンス分析
Google PageSpeed Insights — mobile performance audit of multiscan.app · checked Mar 6, 2026
証拠および外部報告書
このサイトによって何か影響を受けましたか?
アカウント資格情報、個人情報、支払い情報を入力した場合、またはこのドメインからファイルをダウンロードした場合は、すぐに対処してください。インシデントを報告し、自分自身を守るのに役立つリソースを以下に示します。
お住まいの地域の当局へ報告してください
サイバー犯罪の公式連絡先 または 苦情草稿を作成する → を取得するには、国を選択してください。
このレポートについて: multiscan.app
このレポートは、PhishDestroy が入手できる最新の保管証拠を示します。ソースのタイムスタンプが利用可能な場合には表示されます。入手可能性とベンダーの判断は収集後に変更される可能性があります。
キャプチャされたサイトにはページ タイトル “AMLBot - Comprehensive AML Compliance Solutions for Crypto” が表示されており、AMLBot になりすましている可能性があります。
2026年8月6日 の時点で、multiscan.app は 15 セキュリティ エンジンから検出されました。
このリストが不正確であると思われる場合は、異議申し立てを提出する までご連絡ください。当社の方法論について詳しくは、よくある質問ページ をご覧ください。
任意のドメインを確認する
保存されたブロックリスト、WHOIS、DNS、および公開スキャン証拠を使用した脅威分析
今すぐスキャンフィッシングを報告する
不審なドメインを当社の脅威データベースに報告してください — コミュニティを守りましょう
レポートリアルタイム脅威情報フィード
最近のフィッシングレポートと観察された可用性の変化
監視最新情報を入手し、安全を確保しましょう
リアルタイムの脅威を監視するか、誤検知だと思われる場合はこのリストに異議を申し立ててください