Notification and current-status evidence
The sent-report ledger records the first outgoing report at .
The recorded recipient is abuse@nicenic.net.
The latest stored availability evidence still shows the domain reachable; 6 months has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
starknetstaking[.]com
Verificação de phishing e segurança de starknetstaking.com
“404: This page could not be found.”
starknetstaking.com — Erro no servidor (HTTP 523). Representação da marca: StarkNet; Tipo de golpe: Investment Scam. Resumo das evidências: VirusTotal 1/93 (SOCRadar); Spamhaus DBL_PHISH; 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 78/100. Registrador: NiceNIC.
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
Evidence Analysis
The domain starknetstaking.com was registered on February 21, 2026 through NiceNIC International Group Co., Limited. DNS resolution points to 172.67.195.228, an address owned by AS13335 Cloudflare, Inc. and geolocated to the United States. The authoritative nameservers are clay.ns.cloudflare.com and molly.ns.cloudflare.com, indicating the site is fully proxied behind Cloudflare’s network and is served over HTTP/3. The SSL certificate presented is issued by Google Trust Services under the WE1 identifier, confirming the use of a valid TLS certificate.
An HTTP request returns status code 523, suggesting the origin server is unreachable, and the page title returned is "404: This page could not be found." The site is currently listed as taken offline. Threat intelligence records classify the domain as a brand‑impersonation infrastructure targeting the StarkNet ecosystem, with an associated scam type of investment scam. The domain appears on three security blocklists, including PhishDestroy, MetaMask, and SEAL, and it has been flagged by one of ninety‑three vendors on VirusTotal, indicating at least a single detection of malicious behavior. The Gridinsoft trust score is 0 out of 100, reinforcing the low trust assessment.
While the exact malicious payload or phishing lure has not been captured due to the 523 response, the combination of a recent registration, use of a reputable SSL certificate, Cloudflare hosting, and inclusion on multiple blocklists strongly suggests a deliberate attempt to lure StarkNet users into fraudulent investment schemes. Defenders should continue to block the domain at network perimeter devices, update DNS filtering and browser safebrowsing lists, and monitor for any future re‑activation of the domain or related infrastructure. Additional analysis should focus on historic DNS queries and any observed traffic patterns that could reveal the underlying command‑and‑control or payment endpoints.
Cobertura dos dados12 recorded checks
Inteligência de segurança de rede Registrar context
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Captura armazenada
Inteligência de Domínios
Detalhes técnicosDNS, SANs do SSL, carimbos de data e hora
ICANN OVERSIGHT
Credenciamento e contexto RAA
Credenciamento e contexto RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Latest Classified Outcome 2026-08-09 02:50:30 UTC
Tecnologias · 2 identified
Web infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
Análise do VirusTotal
Evidências arquivadas
Análise de desempenho do site
Google PageSpeed Insights — mobile performance audit of starknetstaking.com · checked Apr 28, 2026
Evidências e relatórios externosIndependent lookups and source reports
“Solana wallet drainer. drained all my tokens from phantom wallet”
PD-20260203-064E78 Recipient: abuse@nicenic.net Victim safety and official reportingImmediate actions and verified reporting channels
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.