Notification and current-status evidence
The sent-report ledger records the first outgoing report at . A report was sent to the recorded registrar; contact details remain in Domain Intelligence. The latest stored availability evidence still shows the domain reachable; 14 days has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
magiclink[.]app
“Magic Link — Jack”
Сводка доказательств
The domain magiclink.app is currently flagged as a high‑risk generic phishing site. Registration data shows it was created on 18 October 2023 through Namecheap Inc., and the authoritative nameservers are ns-115.awsdns-14.com, ns-1278.awsdns-31.org, ns-1801.awsdns-33.co.uk, and ns-961.awsdns, indicating use of Amazon Route 53 DNS. DNS resolution points to the IPv4 address 76.76.21.21, which is the sole host observed for the domain. Threat intel lists the domain on one public blocklist and confirms that the anti‑phishing service PhishDestroy has already blocked it.
VirusTotal analysis reports that 2 of 91 scanned security vendors flagged the domain, confirming the presence of malicious indicators despite the low overall detection count. The domain remains active as of the latest check on 27 July 2026. No public page title, SSL certificate details, HTTP response codes, or Safe Browsing verdicts are available in the current dataset, so the exact content and transport security posture cannot be verified. Consequently, defenders should assume the site is intended to harvest credentials or deliver further malicious payloads.
Recommended mitigation steps include adding 76.76.21.21 and magiclink.app to network‑level deny lists, updating email and web gateway filters to block the domain, and monitoring Namecheap registration feeds for any related domains created after the same date. Continuous re‑scanning with VirusTotal and other sandbox services is advised to capture any evolving payloads. Organizations should also educate end‑users about unsolicited communications that reference “magiclink” patterns, as attackers often employ such naming to increase credibility.
Снимок отправленных доказательств
- Отправлено
- Записи журнала
- 1
- ID дела
PD-20260727-83EAA4- PDF-файл
- PDF с доказательствами
Правовое основание
Полный текст доказательств
Policy Violations: Domain Registration Agreement prohibits hacking, misuse of domain to conduct attacks, scam and fraudulent activities; AUP allows immediate suspension
Applicable Laws: CFAA 18 U.S.C. §1030, Wire Fraud 18 U.S.C. §1343, CAN-SPAM Act
Data Coverage
Процесс реагирования на угрозы
Проверка по блок-листам
10 внешних источников под наблюдением · снимок от 11.08.2026
10 внешних источников под наблюдением Совпадений нет
Хронология обнаружения
-
Первая запись
Первое сохранённое значение: Доступен
Сообщения сообщества
Сообщили 0 участников сообщества; впервые замечено 27.07.2026
- Уникальные URL
- 1
Данные сообщества
1 сообщение сообщества
КатегорияIMPERSONATION
Brand abuse: phishing, credential harvesting, impersonation, impersonating Magic (Fortmatic)
Сохранённый снимок
Аналитика доменов
Технические деталиDNS, имена TLS и временные метки
ICANN OVERSIGHT
Аккредитация и контекст RAA
Аккредитация и контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Технологии
Выявлено 3 технологии с высокой уверенностью
Анализ VirusTotal
Архивные доказательства
Анализ производительности сайта
Google PageSpeed Insights — mobile performance audit of magiclink.app · checked Jul 27, 2026
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание