Notification and current-status evidence
The sent-report ledger records the first outgoing report at . A report was sent to the recorded registrar; contact details remain in Domain Intelligence. The latest stored availability evidence still shows the domain reachable; 2 months has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
evobyt[.]ro
“IIS Windows”
Сводка доказательств
PhishDestroy identifies **evobyt.ro** as an active cryptocurrency wallet phishing domain designed to deceive users into revealing sensitive wallet credentials or private keys. The threat actor behind this domain has registered it specifically to mimic legitimate wallet interfaces, likely targeting customers of popular cryptocurrency platforms such as MetaMask. Upon visiting, users are prompted to enter their seed phrases, recovery keys, or login credentials into fraudulent forms that harvest this data for unauthorized access to victim wallets. This domain abuses legitimate hosting infrastructure (IP 193.33.24.68) to appear credible and hosts cloned login pages that closely replicate authentic wallet interfaces. This domain was flagged by security blocklists and blocked by MetaMask, indicating confirmed malicious intent. The domain evobyt.ro was registered through ICI Registrar on November 28, 2017, and currently appears on one known security blocklist. As of this report, VirusTotal scans using 95 antivirus engines returned zero detections, suggesting it remains undetected by many security solutions despite its malicious activity. If you have visited evobyt.ro or entered any credentials or wallet-related information, immediately revoke access from your wallet, transfer assets to a new wallet, and scan your device for malware using a trusted antivirus tool. Never reuse passwords or seed phrases across platforms. Report any suspicious activity to your wallet provider and consider enabling multi-factor authentication on all cryptocurrency accounts. Stay vigilant and verify URLs through official sources before entering sensitive information.
Снимок отправленных доказательств
- Отправлено
- Записи журнала
- 1
- ID дела
PD-20260514-A65FB0- Заголовок сохранённой страницы
- IIS Windows
- PDF-файл
- PDF с доказательствами
Правовое основание
Полный текст доказательств
Illegal Activities: Active phishing operation targeting victims
Fraud & Deception: Impersonation of legitimate services
Identity Theft: Collection of credentials under false pretenses
Applicable Laws (Unknown):
International Anti-Cybercrime Regulations
Budapest Convention on Cybercrime
Universal Fraud Prevention Laws
Phishing activities violate international cybercrime conventions and Unknown's domestic fraud laws.
Action Required: This evidence-backed report demonstrates clear violations requiring suspension per your policies. Continued hosting exposes your organization to regulatory scrutiny and potential legal liability.
Data Coverage
Данные сетевой безопасности
Процесс реагирования на угрозы
Проверка по блок-листам
10 внешних источников под наблюдением · снимок от 10.08.2026
8 внешних источников под наблюдением Совпадений нет
Анализ VirusTotal
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание