Why this matters — ICANN RAA §3.18 obligation
On PhishDestroy delivered an evidence-backed abuse report
to abuse@contabo.de with VirusTotal detections, urlscan capture, legal violations, and full screenshot evidence.
More than 29 days later, the phishing infrastructure remains reachable
.
Under ICANN RAA §3.18 accredited registrars are contractually obliged to “take reasonable and prompt steps to investigate and respond appropriately to any reports of abuse.” Silence beyond 24 hours after a documented notification with verifiable evidence is not a timing issue — it is a policy decision to let the operation continue. PhishDestroy\'s position: where a registrar fails to act on clear evidence, the registrar has aligned itself with the operator of the scheme and bears co-responsibility for downstream harm caused to victims from the moment of notification onward.
mx-flow[.]de
Проверка домена mx-flow.de на фишинг и безопасность
“mx-flow”
mx-flow.de: VirusTotal — 5 срабатываний из 91. Проверьте DNS, SSL, регистратора, блок-листы и данные об угрозах.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
PhishDestroy first recorded mx-flow.de on Jul 3, 2026. This English evidence brief is rebuilt from the current structured observations stored for the report. The current evidence score, computed from those stored observations, is 80/100.
The latest stored availability state is “Last known active” (HTTP 301) on Aug 2, 2026 at 00:32 UTC. This is a reachability snapshot, not proof of the cause of any outage, restriction, or status change.
VirusTotal returned 5 detections from 91 scanners in the stored check on Jul 3, 2026 at 14:30 UTC. The independent blocklist snapshot recorded 0 matches across 10 configured external sources on Aug 2, 2026 at 04:20 UTC. PhishDestroy's own listing is excluded from that count. A zero-match snapshot is not a safety verdict.
Other stored evidence. Google Safe Browsing stored no positive flag on Jul 3, 2026 at 14:25 UTC. This time-bound result is not evidence of safety. AlienVault OTX stored 0 pulse references on Jul 3, 2026 at 14:31 UTC. OTX pulses are community-intelligence references, not vendor verdicts. The Spamhaus DBL snapshot stored no positive result on Jul 3, 2026 at 16:30 UTC. That result is not evidence of safety. A URLScan capture is stored from Jul 3, 2026 at 14:20 UTC.
Stored context lists IP address 213.136.93.167, apparent target Adobe. Except for the registration date, these fields do not share a source timestamp in this report and may change.
Treat these as stored, time-bound observations rather than a live safety guarantee. Source verdicts and reachability can change, and zero or missing vendor matches never prove that a domain is safe. Avoid interacting with the domain while uncertainty remains, and use the appeal process if this report is inaccurate.
Данные сетевой безопасности
Pipeline реагирования на угрозы
Статус в публичных блок-листах
Технологии · 1 identified
Apache is a free and open-source cross-platform web server software.
httpd.apache.org 100% уверенностиАнализ VirusTotal
Анализ производительности сайта
Google PageSpeed Insights — mobile performance audit of mx-flow.de · checked Jul 3, 2026
Доказательства и внешние отчеты
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Об этом отчете: mx-flow.de
В этом отчете представлены последние сохраненные доказательства, доступные PhishDestroy. Временные метки источника отображаются там, где они доступны; Вердикты о доступности и поставщика могут измениться после сбора.
Захваченный сайт отображал заголовок страницы “mx-flow” и мог выдавать себя за Adobe.
Начиная с 02.08.2026, mx-flow.de обнаруживался механизмами безопасности 5.
Если вы считаете, что это объявление неточно, подать апелляцию. Чтобы узнать о нашей методологии, посетите Страница часто задаваемых вопросов.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание