Notification and current-status evidence
The sent-report ledger records the first outgoing report at . A report was sent to the recorded registrar; contact details remain in Domain Intelligence. The latest stored availability evidence still shows the domain reachable; 5 months has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
10mbeforevaientine[.]online
“10M MCAP BEFORE VALENTINES”
Сохранённое наблюдение
Зафиксированное различие заголовков
Сводка доказательств
The domain 10mbeforevaientine.online was registered on February 21, 2026, through NiceNIC International Group Co., Limited, and remains active as of July 25, 2026. Infrastructure analysis reveals it resolves to IP address 188.114.97.3, hosted on Cloudflare's network (AS13335) with nameservers chloe.ns.cloudflare.com and tadeo.ns.cloudflare.com. The site employs Cloudflare technologies and HTTP/3, returning an HTTP 301 redirect status. Its SSL certificate is issued by Google Trust Services (WE1), a common configuration for phishing sites leveraging Cloudflare's proxy services. The page title, '10M MCAP BEFORE VALENTINES,' suggests a cryptocurrency-related scam, likely impersonating a token or project giveaway timed around Valentine's Day.
This aligns with the domain's creation date, approximately one week before February 14, 2026. No specific brand impersonation is confirmed from available data, but the phrasing indicates a high-value incentive scam targeting cryptocurrency users. Detection data shows the domain is flagged by four of 93 security vendors on VirusTotal and appears on two security blocklists, including PhishDestroy and ScamSniffer. Scamadviser assigns it a trust score of 29 out of 100, further indicating malicious intent. The domain's use of Cloudflare nameservers and hosting is consistent with phishing infrastructure, as these services are frequently abused to obscure origin servers and evade takedowns.
Defenders should treat this domain as high-risk. Network-level blocking is recommended for the domain and its resolving IP. Security teams should monitor for related domains registered through NiceNIC or using similar naming patterns (e.g., time-sensitive crypto giveaways). Additional analysis of the redirect target and any associated cryptocurrency wallets could provide further attribution, though such details are not currently available in the provided intelligence.
Снимок отправленных доказательств
- Отправлено
- Записи журнала
- 1
- ID дела
PD-20260213-E09E2C- Заголовок сохранённой страницы
- 10M MCAP BEFORE VALENTINES
- PDF-файл
- PDF с доказательствами
Полный текст доказательств
Policy Violations: “Services may be used only for lawful purposes… fraud, abuse and illegal activity prohibited. Violations may result in immediate suspension.” + dedicated abuse handling and takedown
Applicable Laws: Crimes Ordinance Cap.200 (Fraud), Theft Ordinance Cap.210 §16A (fraud by deception), Personal Data (Privacy) Ordinance Cap.486
Data Coverage
Сигналы безопасности
Данные сетевой безопасности
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Hagezi Threat Feed | 10mbeforevaientine.online |
malicious | Sinkholed |
Процесс реагирования на угрозы
Проверка по блок-листам
10 внешних источников под наблюдением · снимок от 11.08.2026
9 внешних источников под наблюдением Совпадений нет
Сохранённые доказательства результата
Результат и атрибуция блокировки
- Результат
redirected- Доступность
reachable_redirect- Причина
http_redirect- Уверенность
- 80%
- Первое наблюдение
- Последнее наблюдение
SHA-256 доказательства 607e68795585
Хронология обнаружения
-
Статус домена
Доступен → Недоступен
-
Cloudflare Radar
Сканирование Cloudflare Radar сохранено · Открыть сканирование
-
Cloudflare Radar
Сканирование Cloudflare Radar сохранено · Открыть сканирование
-
Доступность
Первое сохранённое значение: Неизвестно
993d00c35140 -
Доступность
Неизвестно → Перенаправлен
84a345d4a4ad -
Доступность
Перенаправлен → Неизвестно
c46f2c37f40c -
Доступность
Неизвестно → Перенаправлен
144524ffa99d -
Доступность
Перенаправлен → Неизвестно
7cebcfd4071c -
Доступность
Неизвестно → Перенаправлен
f833523f5219 -
Доступность
Перенаправлен → Неизвестно
ca255b61650a
Показать все (5)
-
Доступность
Неизвестно → Перенаправлен
18c781f6e67a -
Доступность
Перенаправлен → Неизвестно
d8f7d37d7f95 -
Доступность
Неизвестно → Перенаправлен
0639cbeb96cd -
Доступность
Перенаправлен → Неизвестно
afa49a2b04dd -
Доступность
Неизвестно → Перенаправлен
607e68795585
Сообщения сообщества
Сообщил 1 участник сообщества; впервые замечено 12.02.2026
- Сохранённые сообщения
- 1
- Уникальные URL
- 1
Сохранённый снимок
Аналитика доменов
Технические деталиDNS, имена TLS и временные метки
ICANN OVERSIGHT
Аккредитация и контекст RAA
Аккредитация и контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Анализ VirusTotal
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание