Why this matters — ICANN RAA §3.18 obligation & victim-assistance
On PhishDestroy delivered an evidence-backed abuse report
(repeated 5 times, most recently ) to support@nicenic.net with VirusTotal detections, urlscan capture, legal violations, and full screenshot evidence.
More than 5 months later, the phishing infrastructure remains reachable
.
Under ICANN RAA §3.18 accredited registrars are contractually obliged to “take reasonable and prompt steps to investigate and respond appropriately to any reports of abuse.” Silence beyond 24 hours after a documented notification with verifiable evidence is not a timing issue — it is a policy decision to let the operation continue. PhishDestroy\'s position: where a registrar fails to act on clear evidence, the registrar has aligned itself with the operator of the scheme and bears co-responsibility for downstream harm caused to victims from the moment of notification onward.
Victim-assistance obligation. If NiceNIC International Group Co., Limited doesn't consider the listed detections enough proof — that is interesting in itself, given the volume of independent vendor confirmations. But after 5 separate notifications over 5 months, with the operation still active, the registrar took no measurable action to mitigate the harm caused by their client. The reasonable next step is direct help to any identified victims — contact & payment-trail disclosure, abuse-thread transcripts, registrant data preservation — since the registrar chose, by inaction, to extend the window of damage.
web3amlchecking[.]com
Проверка домена web3amlchecking.com на фишинг и безопасность
“AML Check - The full-fledged crypto compliance solution”
web3amlchecking.com: VirusTotal — 12 срабатываний из 91. Проверьте DNS, SSL, регистратора, блок-листы и данные об угрозах.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
PhishDestroy first recorded web3amlchecking.com on Nov 28, 2025. This English evidence brief is rebuilt from the current structured observations stored for the report. The current stored risk score is 100/100.
The latest stored availability state is “Last known active” (HTTP 308) on Aug 2, 2026 at 00:52 UTC. This is a reachability snapshot, not proof of the cause of any outage, restriction, or status change.
VirusTotal returned 12 detections from 91 scanners in the stored check on Jul 26, 2026 at 05:00 UTC. The independent blocklist snapshot recorded 4 matches (ScamSniffer, Polkadot, Enkrypt, Codeesura) across 10 configured external sources on Aug 2, 2026 at 00:20 UTC. PhishDestroy's own listing is excluded from that count.
Other stored evidence. Google Safe Browsing stored no positive flag on Mar 2, 2026 at 21:22 UTC. This time-bound result is not evidence of safety. AlienVault OTX stored 0 pulse references on Mar 1, 2026 at 17:20 UTC. OTX pulses are community-intelligence references, not vendor verdicts. Spamhaus DBL stored the result DBL_PHISH on Jul 14, 2026 at 16:37 UTC. A URLScan capture is stored from Feb 27, 2026 at 02:36 UTC.
Stored context lists registrar NiceNIC International Group Co., Limited, IP address 91.92.242.155, registration date Nov 26, 2025, apparent target LinkedIn. Except for the registration date, these fields do not share a source timestamp in this report and may change.
Treat these as stored, time-bound observations rather than a live safety guarantee. Source verdicts and reachability can change, and zero or missing vendor matches never prove that a domain is safe. Avoid interacting with the domain while uncertainty remains, and use the appeal process if this report is inaccurate.
Данные сетевой безопасности Registrar Integrity Alert
Pipeline реагирования на угрозы
Статус в публичных блок-листах
Сбор доказательств
Аналитика доменов
Технические сведенияDNS, SAN в протоколе SSL, временные метки
НАДЗОР ICANN · СБОР ПОЛУЧЕН
ICANN получила деньги. Подотчётность так и не появилась.
ICANN получила деньги. Подотчётность так и не появилась.
Для этой gTLD указанный выше регистратор работает по договору с ICANN. ICANN взимает ежегодные, переменные и транзакционные сборы, связанные с регистрациями, продлениями и трансферами.
Аккредитация: монетизирована. Подотчётность: пожалуйста, проверьте позже.
Затем начинается магия: ICANN пишет RAA §3.18, регистратор расследует злоупотребления внутри собственной клиентской базы, а жертвы бесплатно предоставляют доказательства, пока каждый уровень ждёт, что действовать начнёт кто-то другой. Если благодаря этому жертвы чувствуют себя в большей безопасности — отлично: счёт сделал своё дело.
История жалоб на злоупотребления · 3 stored reports over 2 days · click to expand
-
Report #1 Escalation 368h still active Feb 9, 2026 · 01:56 UTCESCALATION #3 (368h active): Phishing - web3amlchecking[.]comsupport@nicenic.net
-
Report #2 Escalation 368h still active Feb 9, 2026 · 02:01 UTCESCALATION #4 (368h active): Phishing - web3amlchecking[.]comsupport@nicenic.net
-
Report #3 Escalation 406h still active Feb 10, 2026 · 16:53 UTCESCALATION #5 (406h active): Phishing - web3amlchecking[.]comsupport@nicenic.net
Технологии · 3 identified
Progressive JavaScript framework for building user interfaces.
High-performance HTTP server and reverse proxy, known for stability and low resource usage.
Анализ VirusTotal
Архивные доказательства
Анализ производительности сайта
Google PageSpeed Insights — mobile performance audit of web3amlchecking.com · checked Mar 2, 2026
Доказательства и внешние отчеты Open external tools
Повлиял ли на вас этот сайт?
If you entered account credentials, personal or payment information, or downloaded a file from this domain, take immediate action. Below are resources to help you report the incident and protect yourself.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по вопросам киберпреступности, or create a complaint draft →
About This Report: web3amlchecking.com
This report presents the latest stored evidence available to PhishDestroy. Source timestamps are shown where available; availability and vendor verdicts can change after collection.
The site displays a page titled “AML Check - The full-fledged crypto compliance solution”, which may be designed to impersonate LinkedIn.
web3amlchecking.com has been flagged by 12 security vendors as of August 1, 2026.
Если вы считаете, что эта информация неверна, вы можете подать апелляцию. Для получения более подробной информации о нашей методологии посетите наш Страница «Часто задаваемые вопросы».
Проверить любой домен
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
ReportПоток оперативных данных об угрозах
Recent phishing reports and observed availability changes
MonitorБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание
