Why this matters — ICANN RAA §3.18 obligation & victim-assistance
On PhishDestroy delivered an evidence-backed abuse report
(repeated 6 times, most recently ) to abuse@spaceship.com with the evidence stored for the case at that time.
More than 6 months later, the phishing infrastructure remains reachable
.
Under ICANN RAA §3.18 accredited registrars are contractually obliged to “take reasonable and prompt steps to investigate and respond appropriately to any reports of abuse.” Silence beyond 24 hours after a documented notification with verifiable evidence is not a timing issue — it is a policy decision to let the operation continue. PhishDestroy\'s position: where a registrar fails to act on clear evidence, the registrar has aligned itself with the operator of the scheme and bears co-responsibility for downstream harm caused to victims from the moment of notification onward.
Victim-assistance obligation. If Spaceship, Inc. doesn't consider the listed detections enough proof — that is interesting in itself, given the volume of independent vendor confirmations. But after 6 separate notifications over 6 months, with the operation still active, the registrar took no measurable action to mitigate the harm caused by their client. The reasonable next step is direct help to any identified victims — contact & payment-trail disclosure, abuse-thread transcripts, registrant data preservation — since the registrar chose, by inaction, to extend the window of damage.
lucklex[.]com
Verificação de phishing e segurança de lucklex.com
“Lucklex: Most Popular Online Crypto Casino Based on Blockchain”
lucklex.com — Último ativo conhecido (HTTP 200). Representação da marca: Genericcrypto; Tipo de golpe: Crypto Scam. Resumo das evidências: VT 14/91 (ADMINUSLabs, alphaMountain.ai, BitDefender, Chong Lua Dao, CyRadar); URLQuery 1 alert; URLScan malicious; GSB no flag; Spamhaus DBL_PHISH; BL 0; PD 100/100. Registrador: Spaceship.
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
This report analyzes the domain lucklex.com, which presents itself as an online crypto casino operating on blockchain technology. The site impersonates a legitimate cryptocurrency gambling brand. The primary threat posed by this domain is a cryptocurrency scam, designed to defraud users by soliciting deposits or personal information under false pretenses, with no intention of providing legitimate gambling services.
Technical analysis reveals significant risk indicators. VirusTotal flagged the domain with 15 detections out of 95 security vendors. It is specifically flagged by ADMINUSLabs, alphaMountain.ai, BitDefender, CRDF, and Ermes, and appears on one blocklist. The domain is hosted on IP address 104.21.50.112 located in the United States, associated with AS13335 Cloudflare, Inc. The domain was registered on 2026-01-18 through registrar Spaceship, Inc. SSL certificate is issued by Google Trust Services / WE1. Nameservers are alec.ns.cloudflare.com and monroe.ns.cloudflare.com.
The domain is currently offline or down. The GridinSoft trust score is 1 out of 100, indicating very low trustworthiness. The combination of recent creation date, high detection rate, and low trust score indicates a high risk level for users encountering this site. Any engagement with this domain should be avoided.
Sinais de segurança
Inteligência de segurança de rede
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DNS4EU | lucklex.com |
malicious | Sinkholed |
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Captura armazenada
Inteligência de Domínios
Detalhes técnicosDNS, SANs do SSL, carimbos de data e hora
ICANN OVERSIGHT
Credenciamento e contexto RAA
Credenciamento e contexto RAA
A ICANN recebeu o pagamento. A responsabilização não chegou.
Para este gTLD, o registrador acima opera sob um contrato com a ICANN. A ICANN cobra taxas anuais, variáveis e baseadas em transações vinculadas a registros, renovações e transferências.
Credenciamento: monetizado. Responsabilização: verifique novamente mais tarde.
Então a mágica começa: a ICANN redige o RAA §3.18, o registrador investiga abusos dentro da própria base de clientes, e as vítimas entregam as provas de graça enquanto cada nível espera que outra pessoa aja. Se isso faz as vítimas se sentirem mais seguras, excelente — a fatura funcionou.
Histórico de denúncias de abuso · 6 stored reports over 86 days · click to expand
-
Report #1 Escalation 23h still active Feb 8, 2026 · 18:29 UTCESCALATION #2 (23h active): Phishing - lucklex[.]comsupport@spaceship.com
-
Report #2 ICANN CC 606h still active Mar 5, 2026 · 01:29 UTCESCALATION #3 (606h active): Phishing - lucklex[.]comabuse@spaceship.com abuse@verisign-grs.com compliance@icann.org
-
Report #3 ICANN CC 639h still active Mar 6, 2026 · 10:51 UTCESCALATION #4 (639h active): Phishing - lucklex[.]comabuse@spaceship.com abuse@verisign-grs.com compliance@icann.org
-
Report #5 ICANN CC 1348h still active Apr 5, 2026 · 02:18 UTCESCALATION #5 (1348h active): Phishing - lucklex[.]comabuse@spaceship.com abuse@verisign-grs.com compliance@icann.org
-
Report #6 ICANN CC 1721h still active Apr 20, 2026 · 15:10 UTCESCALATION #6 (1721h active): Phishing - lucklex[.]comabuse@spaceship.com abuse@verisign-grs.com compliance@icann.org
-
Report #7 ICANN CC 2072h still active May 5, 2026 · 06:52 UTCESCALATION #7 (2072h active): Phishing - lucklex[.]comabuse@spaceship.com abuse@verisign-grs.com compliance@icann.org
Análise do VirusTotal
Evidências arquivadas
Evidências e relatórios externos
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Sobre este relatório: lucklex.com
Este relatório apresenta as últimas evidências armazenadas disponíveis para PhishDestroy. Os carimbos de data/hora de origem são mostrados quando disponíveis; a disponibilidade e os veredictos do fornecedor podem mudar após a coleta.
O site capturado exibia o título da página “Lucklex: Most Popular Online Crypto Casino Based on Blockchain” e pode estar se passando por Genericcrypto.
A partir de 07/08/2026, lucklex.com tinha detecções de mecanismos de segurança 14.
Se você acredita que esta listagem é imprecisa, enviar um recurso. Para conhecer nossa metodologia, acesse o Página de perguntas frequentes.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo