Notification and current-status evidence
The sent-report ledger records the first outgoing report at . A report was sent to the recorded registrar; contact details remain in Domain Intelligence. The latest stored availability evidence still shows the domain reachable; 2 months has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
lllll[.]com
Resumo das evidências
This domain, lllll.com, is identified as a credential harvesting phishing site designed to deceive users into submitting sensitive login credentials through fraudulent web portals. Analysis indicates the domain is currently offline, though historical activity confirms its use in phishing campaigns targeting financial and corporate sectors. No specific brand impersonation has been confirmed, but the infrastructure aligns with generic phishing tactics aimed at broad credential theft. Infrastructure analysis reveals the domain was registered through Alibaba Cloud Computing Ltd. d/b/a HiChina (www.net.cn) on September 01, 1997, an unusually long registration period that may indicate domain squatting or repurposing for malicious use. It resolves to the IP address 208.98.40.10 and has been flagged by 10 of 95 security vendors on VirusTotal, placing it in the 10.5% detection range. The domain appears on one security blocklist, and its Gridinsoft trust score is 0/100, reflecting high confidence in its malicious classification. The unique seed for this threat is e20174, and it is currently blocked by PhishDestroy. Current status indicates the domain has been taken offline, reducing immediate risk to end users. However, the long-standing registration and historical malicious activity warrant continued monitoring. Organizations are advised to implement DNS-based blocking for lllll.com and its associated IP (208.98.40.10) at the perimeter level. Endpoint protection solutions should be updated to include this domain in phishing and malicious URL detection rules. Security teams should review logs for any prior connections to this domain or IP to assess potential compromise. Given the elevated risk level, user awareness training should emphasize the dangers of credential harvesting phishing sites, particularly those mimicking login portals for financial or corporate services.
Instantâneo das evidências enviadas
- Enviado
- Registros do livro-razão
- 1
- ID do caso
PD-20260531-258476- Título da página capturada
- lllll.com/
- Artefato PDF
- Evidência em PDF
Texto completo da evidência
Acceptable Use Policy (AUP): The domain lllll.com is actively engaged in phishing activities, which constitute a clear violation of your AUP prohibiting illegal activities, fraud, and deception.
Terms of Service (TOS): The continued operation of this domain directly contravenes your TOS, which reserves the right to suspend or terminate services for violations related to fraudulent activities.
Applicable Laws (CN):
Cybersecurity Law of the People's Republic of China: This law mandates that network operators must take measures to prevent and mitigate cybersecurity incidents, including phishing.
Criminal Law of the People's Republic of China (Article 286): This article criminalizes fraud and deception, including online scams, which are applicable to the activities conducted by lllll.com.
Regulatory Note: Failure to comply with the outlined policies and applicable laws may result in legal repercussions and regulatory scrutiny. Immediate action is advised to mitigate potential liability.
Data Coverage
Inteligência de segurança de rede
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DNS4EU | lllll.com |
malicious | Sinkholed |
Pipeline de resposta a ameaças
Cobertura de listas de bloqueio
10 fontes externas monitoradas · instantâneo de 11/08/2026
10 fontes externas monitoradas Sem correspondência
Linha do tempo de detecção
-
VirusTotal
8 → 10
Captura armazenada
Inteligência de Domínios
Detalhes técnicosDNS, nomes TLS e datas
ICANN OVERSIGHT
Credenciamento e contexto RAA
Credenciamento e contexto RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Análise do VirusTotal
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo