Notification and current-status evidence
The sent-report ledger records the first outgoing report at .
The recorded recipient is abuse@deneva.co.id.
The latest stored availability evidence still shows the domain reachable; 1 month has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
web-3web[.]com
“Home - web-3 Web - A crypto buy and sell marketplace”
web-3web.com — Непроверенный. Сводка доказательств: VirusTotal 6/91 (ADMINUSLabs, alphaMountain.ai, CRDF, Fortinet, Gridinsoft); PhishDestroy score 83/100. Регистратор: GMO Internet.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
The domain web-3web.com was registered on February 10, 2026 through GMO Internet, Inc. and presently resolves to the IP address 103.147.154.221. DNS records show authoritative name servers ns1.domainesia.net and ns2.domainesia.net, indicating the use of a third‑party DNS provider. As of the report date, the domain remains active and continues to resolve, suggesting the infrastructure is still operational. VirusTotal scans have identified the domain as malicious in 2 of 91 security vendor engines, providing a modest but concrete indication of phishing‑related activity.
Independent threat‑intelligence feeds have placed the domain on a single security blocklist, and it is explicitly listed as blocked by the PhishDestroy service, confirming that at least one anti‑phishing organization has taken action against it. No public information is available regarding the website’s page title, SSL certificate details, or the specific content hosted, leaving the exact phishing lure and target brand undefined. Consequently, the precise technique employed (e.g., credential harvesting page, credential‑stealing redirect) cannot be confirmed without direct content analysis.
Defenders should prioritize immediate mitigation: add web-3web.com and its resolving IP 103.147.154.221 to network‑level blocklists, update DNS filtering policies to deny queries for the domain, and monitor for any related sub‑domains or infrastructure changes. Continuous re‑scanning of the domain through multi‑vendor services is advised to capture any escalation in detection counts. Given the recent creation date and limited detection footprint, the threat remains high due to its active status and confirmed phishing classification, warranting proactive blocking and ongoing observation.
Процесс реагирования на угрозы
Статус в публичных блок-листах
Сохранённый снимок
Аналитика доменов
Технические сведенияDNS, SAN в протоколе SSL, временные метки
ICANN OVERSIGHT
Аккредитация и контекст RAA
Аккредитация и контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Технологии · 4 identified
Smartsupp is a live chat tool that offers visitor recording feature.
www.smartsupp.com 100% уверенностиHTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org 100% уверенностиHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100% уверенностиАнализ VirusTotal
Архивные доказательства
Доказательства и внешние отчеты
PD-20260727-8DF780 Recipient: abuse@deneva.co.id Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание