Why this matters — ICANN RAA §3.18 obligation & victim-assistance
On PhishDestroy delivered an evidence-backed abuse report
(repeated 6 times, most recently ) to domainabuse@tucows.com with the evidence stored for the case at that time.
More than 5 months later, the phishing infrastructure remains reachable
.
Under ICANN RAA §3.18 accredited registrars are contractually obliged to “take reasonable and prompt steps to investigate and respond appropriately to any reports of abuse.” Silence beyond 24 hours after a documented notification with verifiable evidence is not a timing issue — it is a policy decision to let the operation continue. PhishDestroy\'s position: where a registrar fails to act on clear evidence, the registrar has aligned itself with the operator of the scheme and bears co-responsibility for downstream harm caused to victims from the moment of notification onward.
Victim-assistance obligation. If Tucows Domains Inc. doesn't consider the listed detections enough proof — that is interesting in itself, given the volume of independent vendor confirmations. But after 6 separate notifications over 5 months, with the operation still active, the registrar took no measurable action to mitigate the harm caused by their client. The reasonable next step is direct help to any identified victims — contact & payment-trail disclosure, abuse-thread transcripts, registrant data preservation — since the registrar chose, by inaction, to extend the window of damage.
pokoplay[.]com
pokoplay.com のフィッシング・安全性チェック
“Google Chrome – den schnellen und sicheren Browser von Google jetzt herunterl...”
pokoplay.com:VirusTotal の 93 エンジン中 14 件が検出。DNS、SSL、レジストラ、ブロックリスト、脅威情報を確認できます。
元のフォレンジック記録を保持するため、下の PhishDestroy AI 詳細分析は英語のままです。
PhishDestroy first observed pokoplay.com on Feb 26, 2026. Evidence score: 97/100 (a triage score, not a probability).
Threat signals: 14 of 93 VirusTotal engines flagged the domain on Jul 18, 2026 at 18:45 UTC.
The endpoint responded with HTTP 403 on Aug 5, 2026 at 22:14 UTC, but access was restricted; content availability remains unconfirmed.
Other observations: No external blocklist matches were recorded in the snapshot from Aug 6, 2026 at 06:20 UTC. Google Safe Browsing recorded no flag on Mar 2, 2026 at 20:52 UTC. AlienVault OTX recorded 0 community pulse references on Mar 1, 2026 at 05:01 UTC. Spamhaus DBL recorded no positive result on Jul 14, 2026 at 06:33 UTC. URLScan captured the domain on Mar 28, 2026 at 11:13 UTC. Negative or missing results do not establish safety.
Context: registrar Tucows Domains Inc., IP address 142.251.208.4, registration date Feb 21, 2026, apparent target Google. Infrastructure details may have changed since collection.
This report summarizes time-bound observations, not a live guarantee. Avoid interacting with the domain; submit an appeal if the report is inaccurate.
脅威対応 Pipeline
公開ブロックリスト登録状況
保存済みキャプチャ
ドメイン・インテリジェンス
技術的な詳細DNS、SSL SAN、タイムスタンプ
ICANN OVERSIGHT
認定と RAA の背景
認定と RAA の背景
ICANNには支払いが済んだ。説明責任は届かなかった。
このgTLDでは、上記のレジストラはICANNとの契約に基づいて運営されています。ICANNは、登録、更新、移管に連動する年間手数料、変動手数料、および取引ベースの手数料を徴収します。
認定:収益化済み。説明責任:後ほどもう一度ご確認ください。
そして魔法が始まります。ICANNがRAA §3.18を書き、レジストラは自らの顧客基盤内の不正利用を自ら調査し、被害者は証拠を無償で提供する一方、各層は誰か別の者が動くのを待ちます。それで被害者が少しでも安全になった気がするなら、結構なことです――請求書は仕事を果たしたわけです。
不正利用報告履歴 · 6 stored reports over 105 days · click to expand
-
Report #1 Escalation 342h still active Feb 8, 2026 · 18:32 UTCESCALATION #2 (342h active): Phishing - pokoplay[.]comdomainabuse@tucows.com
-
Report #2 ICANN CC 925h still active Mar 5, 2026 · 01:30 UTCESCALATION #3 (925h active): Phishing - pokoplay[.]comdomainabuse@tucows.com abuse@verisign-grs.com compliance@icann.org
-
Report #3 ICANN CC 958h still active Mar 6, 2026 · 11:12 UTCESCALATION #4 (958h active): Phishing - pokoplay[.]comdomainabuse@tucows.com abuse@verisign-grs.com compliance@icann.org
-
Report #5 ICANN CC 1995h still active Apr 18, 2026 · 18:51 UTCESCALATION #5 (1995h active): Phishing - pokoplay[.]comdomainabuse@tucows.com abuse@verisign-grs.com compliance@icann.org
-
Report #6 ICANN CC 2393h still active May 5, 2026 · 08:56 UTCESCALATION #6 (2393h active): Phishing - pokoplay[.]comdomainabuse@tucows.com abuse@verisign-grs.com compliance@icann.org
-
Report #7 ICANN CC 2847h still active May 24, 2026 · 06:32 UTCESCALATION #7 (2847h active): Phishing - pokoplay[.]comdomainabuse@tucows.com abuse@verisign-grs.com compliance@icann.org
VirusTotalによる分析
証拠および外部報告書
このサイトによって何か影響を受けましたか?
アカウント資格情報、個人情報、支払い情報を入力した場合、またはこのドメインからファイルをダウンロードした場合は、すぐに対処してください。インシデントを報告し、自分自身を守るのに役立つリソースを以下に示します。
お住まいの地域の当局へ報告してください
サイバー犯罪の公式連絡先 または 苦情草稿を作成する → を取得するには、国を選択してください。
このレポートについて: pokoplay.com
このレポートは、PhishDestroy が入手できる最新の保管証拠を示します。ソースのタイムスタンプが利用可能な場合には表示されます。入手可能性とベンダーの判断は収集後に変更される可能性があります。
キャプチャされたサイトにはページ タイトル “Google Chrome – den schnellen und sicheren Browser von Google jetzt herunterladen” が表示されており、Google になりすましている可能性があります。
2026年8月6日 の時点で、pokoplay.com は 14 セキュリティ エンジンから検出されました。
このリストが不正確であると思われる場合は、異議申し立てを提出する までご連絡ください。当社の方法論について詳しくは、よくある質問ページ をご覧ください。
任意のドメインを確認する
保存されたブロックリスト、WHOIS、DNS、および公開スキャン証拠を使用した脅威分析
今すぐスキャンフィッシングを報告する
不審なドメインを当社の脅威データベースに報告してください — コミュニティを守りましょう
レポートリアルタイム脅威情報フィード
最近のフィッシングレポートと観察された可用性の変化
監視最新情報を入手し、安全を確保しましょう
リアルタイムの脅威を監視するか、誤検知だと思われる場合はこのリストに異議を申し立ててください