Notification and current-status evidence
The sent-report ledger records the first outgoing report at . A report was sent to the recorded registrar; contact details remain in Domain Intelligence. The latest stored availability evidence still shows the domain reachable; 4 months has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
nextrade26[.]me
Resumo das evidências
Analysis of nextrade26.me indicates a credential phishing domain registered on March 23, 2026, through Fewmoretaps OU d/b/a Trustname.com. The domain resolved to IP address 172.67.140.111, hosted behind Cloudflare infrastructure in Canada, utilizing Cloudflare nameservers (elle.ns.cloudflare.com, woz.ns.cloudflare.com) and a Let's Encrypt SSL certificate (E7). HTTP/3 and Cloudflare Browser Insights were detected as part of its technical stack, suggesting an attempt to leverage modern web protocols for perceived legitimacy. The page title "Just a moment..." is consistent with Cloudflare's interstitial challenge page, which may have obscured the actual phishing content from automated scans at the time of detection. The domain was flagged by five out of 94 security vendors on VirusTotal and appears on at least one security blocklist.
Scamadviser assigned a trust score of 45/100, while Gridinsoft rated it 0/100, reflecting elevated suspicion. The domain was classified as a credential phishing threat and subsequently blocked by PhishDestroy before being taken offline. No specific brand impersonation or phishing kit details were identified in the available data; the exact content and target remain unconfirmed. Defenders should treat this domain as a confirmed phishing threat.
The use of Cloudflare infrastructure and a valid SSL certificate does not mitigate the risk, as these are commonly exploited to evade detection. Network-level blocking of 172.67.140.111 and monitoring for related domains registered through the same registrar (Fewmoretaps OU/Trustname.com) are recommended. If this domain was observed in logs, credentials submitted should be considered compromised and rotated immediately. Further investigation into the hosting provider's abuse response and Cloudflare's role in obfuscating the malicious content may be warranted.
Instantâneo das evidências enviadas
- Enviado
- Registros do livro-razão
- 1
- ID do caso
PD-1774451773-nextrade26.me- Artefato PDF
- Evidência em PDF
Histórico de denúncias 1
- Denúncia 1 Phishing Abuse Report: nextrade26[.]me
Data Coverage
Inteligência de segurança de rede
Pipeline de resposta a ameaças
Cobertura de listas de bloqueio
10 fontes externas monitoradas · instantâneo de 10/08/2026
10 fontes externas monitoradas Sem correspondência
Inteligência forense
Análise do VirusTotal
Análise de desempenho do site
Google PageSpeed Insights — mobile performance audit of nextrade26.me · checked Mar 22, 2026
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo