Notification and current-status evidence
The sent-report ledger records the first outgoing report at . A report was sent to the recorded registrar; contact details remain in Domain Intelligence. The latest stored availability evidence still shows the domain reachable; 28 days has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
parimatch[.]to
“Parimatch - Play Slots with Bonuses Online”
Сохранённое наблюдение
Зафиксированное различие заголовков
Сводка доказательств
The domain parimatch.to is currently flagged as an active generic phishing site designed to impersonate legitimate betting platforms. Analysis indicates this infrastructure is likely targeting users of the Parimatch brand, a well-known online gambling service, to harvest credentials or financial information. The domain remains operational and poses a high risk to visitors seeking legitimate betting services. Infrastructure analysis reveals the domain was registered on September 17, 2025, through the Government of the Kingdom of Tonga, an uncommon registrar for commercial entities. It resolves to the IP address 158.94.211.126, which has been associated with other suspicious domains in recent months. Detection metrics show that 3 of 95 security vendors on VirusTotal have flagged parimatch.to as malicious, a relatively low but notable detection rate that suggests emerging or evasive phishing tactics. No additional blocklist entries or trust scores from major threat intelligence platforms have been recorded at this time, though the domain's recent creation and limited detection history warrant caution. Current status confirms parimatch.to remains active and accessible, indicating the campaign is ongoing. Users are strongly advised to avoid interacting with this domain, particularly those attempting to access betting or gambling services. Organizations should consider implementing DNS-level blocking for 158.94.211.126 and monitoring for related domains registered through the same registrar. Endpoint protection systems should be updated to include this domain in phishing detection rules, and users should be educated on verifying domain authenticity before entering credentials or financial details.
Снимок отправленных доказательств
- Отправлено
- Записи журнала
- 1
- ID дела
PD-20260712-CCC2A7- Заголовок сохранённой страницы
- Parimatch - Play Slots with Bonuses Online
- PDF-файл
- PDF с доказательствами
Правовое основание
Полный текст доказательств
Illegal Activities: Active phishing operation targeting victims
Fraud & Deception: Impersonation of legitimate services
Identity Theft: Collection of credentials under false pretenses
Applicable Laws (Unknown):
International Anti-Cybercrime Regulations
Budapest Convention on Cybercrime
Universal Fraud Prevention Laws
Phishing activities violate international cybercrime conventions and Unknown's domestic fraud laws.
Action Required: This evidence-backed report demonstrates clear violations requiring suspension per your policies. Continued hosting exposes your organization to regulatory scrutiny and potential legal liability.
Data Coverage
Данные сетевой безопасности
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Cloudflare DNS | parimatch.to |
malicious | Sinkholed |
| Hagezi Threat Feed | parimatch.to |
malicious | Sinkholed |
| DigiCert UltraDNS | parimatch.to |
malicious | Sinkholed |
| CIRA Canadian Shield DNS | parimatch.to |
malicious | Sinkholed |
Процесс реагирования на угрозы
Проверка по блок-листам
10 внешних источников под наблюдением · снимок от 10.08.2026
8 внешних источников под наблюдением Совпадений нет
Casino / Gambling License Verification
Технологии
Выявлена 1 технология с высокой уверенностью
Анализ VirusTotal
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание