Notification and current-status evidence
The sent-report ledger records the first outgoing report at .
The recorded recipient is complaint@gname.com.
The latest stored availability evidence still shows the domain reachable; 2 months has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
korzentx[.]com
korzentx.com — Não verificado. Tipo de golpe: Credential Phishing. Resumo das evidências: VirusTotal 6/91 (BitDefender, ESET, Fortinet, G-Data, Gridinsoft); PhishDestroy score 68/100. Registrador: Gname.
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
This domain, korzentx.com, is identified as a credential-harvesting phishing site designed to mimic legitimate login portals for the purpose of stealing user credentials. Analysis indicates the domain is currently offline, though it previously hosted malicious infrastructure targeting unsuspecting users. No specific brand impersonation has been confirmed, but the generic phishing framework suggests broad targeting across multiple services. Infrastructure analysis reveals the domain was registered on December 27, 2025, through Gname.com Pte. Ltd., a registrar frequently associated with high-risk domains. It resolves to the IP address 188.114.96.3 and has been flagged by 6 of 95 security vendors on VirusTotal, indicating moderate to high detection rates. The domain appears on one security blocklist and has a Gridinsoft trust score of 27 out of 100, further corroborating its malicious nature. Additionally, the domain was included in two threat intelligence pulses on AlienVault OTX, suggesting active tracking by security researchers. The SSL certificate is issued by Google Trust Services, which, while not inherently malicious, is often exploited by threat actors to lend a false sense of legitimacy to phishing sites. Current status confirms the domain has been taken offline, likely in response to detection and mitigation efforts. However, the infrastructure remains a latent threat, as domains of this nature are frequently reactivated or repurposed. Users and organizations are advised to block the domain and its associated IP address at the network level. Security teams should monitor for any re-emergence of korzentx.com or similar domains registered through the same registrar. End users are urged to verify the authenticity of login portals before entering credentials and to report any suspicious activity to their security providers. Proactive measures, such as implementing multi-factor authentication and conducting regular security awareness training, are recommended to mitigate the risk of credential theft.
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Captura armazenada
Inteligência de Domínios
Detalhes técnicosDNS, SANs do SSL, carimbos de data e hora
ICANN OVERSIGHT
Credenciamento e contexto RAA
Credenciamento e contexto RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Tecnologias · 6 identified
Proton Mail is the world’s largest secure email service with over 70 million users. Available on Web, iOS, Android, and desktop. Protected by Swiss privacy law.
proton.me 100% de confiançaVue.js is an open-source model–view–viewmodel JavaScript framework for building user interfaces and single-page applications.
vuejs.org 100% de confiançaHTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org 100% de confiançaCloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com 100% de confiançaHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100% de confiançaAnálise do VirusTotal
Análise de desempenho do site
Google PageSpeed Insights — mobile performance audit of korzentx.com · checked Jun 25, 2026
Evidências e relatórios externos
“I got added to a WhatsApp group and they were talking about crypto investing and sending signals, i didn't act immediately and after time i saw the signals were good so i then started speaking to one of the admins of the group and they were saying i can use any platform of my choice but they suggest using Korzentx.com as it had all the pairs they were sending. I joined them and added funds and things were going well and i kept adding funds and did not suspect anything as i did a withdrawal and i”
PD-20260610-946C27 Recipient: complaint@gname.com Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo