Notification and current-status evidence
The sent-report ledger records the first outgoing report at .
The recorded recipient is abuse@porkbun.com.
The latest stored availability evidence still shows the domain reachable; 5 months has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
rosplat[.]lat
“PayLink Form”
rosplat.lat — Não verificado. Tipo de golpe: Credential Phishing. Resumo das evidências: VirusTotal 3/91 (alphaMountain.ai, CRDF, Gridinsoft); PhishDestroy score 71/100. Registrador: Porkbun.
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
This domain, rosplat.lat, carries an elevated risk level as a generic phishing threat, specifically designed to mimic a PayLink Form to steal sensitive credentials. The domain was flagged for its deceptive nature, aiming to trick users into submitting personal or financial information under the guise of a legitimate payment link service. PhishDestroy assesses this as a clear credential harvesting operation, given the page title and lack of legitimate association with any known payment platform.
Technical indicators paint a concerning picture: VirusTotal reports that 2 out of 95 security vendors flagged this domain, confirming malicious activity. The domain was registered through Porkbun LLC and created on February 28, 2026, indicating a relatively recent setup for likely short-lived phishing campaigns. It resolves to IP address 91.215.42.72, and its SSL certificate is issued by Let's Encrypt (R12), a common tactic used by phishers to appear legitimate. Importantly, the domain has been taken offline and appears on only 1 security blocklist, suggesting it may have evaded broader detection. The trust score is low due to these red flags.
To protect against this specific threat, users should never enter credentials or payment details on any site claiming to be a PayLink Form unless they have independently verified the URL through official channels. Always check for HTTPS and inspect the domain name carefully—rosplat.lat is not associated with any legitimate payment service. If you have already submitted information, change passwords immediately and monitor accounts for unauthorized activity. Report the domain to your email provider or security team, and consider using a password manager that warns against visiting known phishing sites. Staying vigilant against unsolicited payment links is key to avoiding such traps.
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Captura armazenada
Inteligência de Domínios
Detalhes técnicosDNS, SANs do SSL, carimbos de data e hora
ICANN OVERSIGHT
Credenciamento e contexto RAA
Credenciamento e contexto RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Análise do VirusTotal
Evidências arquivadas
Evidências e relatórios externos
PD-20260228-EF1498 Recipient: abuse@porkbun.com Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo