Why this matters — ICANN RAA §3.18 obligation & victim-assistance
On PhishDestroy delivered an evidence-backed abuse report
(repeated 4 times, most recently ) to abuse@verisign-grs.com with the evidence stored for the case at that time.
More than 5 months later, the phishing infrastructure remains reachable
.
Under ICANN RAA §3.18 accredited registrars are contractually obliged to “take reasonable and prompt steps to investigate and respond appropriately to any reports of abuse.” Silence beyond 24 hours after a documented notification with verifiable evidence is not a timing issue — it is a policy decision to let the operation continue. PhishDestroy\'s position: where a registrar fails to act on clear evidence, the registrar has aligned itself with the operator of the scheme and bears co-responsibility for downstream harm caused to victims from the moment of notification onward.
Victim-assistance obligation. If Dominet (HK) Limited doesn't consider the listed detections enough proof — that is interesting in itself, given the volume of independent vendor confirmations. But after 4 separate notifications over 5 months, with the operation still active, the registrar took no measurable action to mitigate the harm caused by their client. The reasonable next step is direct help to any identified victims — contact & payment-trail disclosure, abuse-thread transcripts, registrant data preservation — since the registrar chose, by inaction, to extend the window of damage.
drakebi[.]com
drakebi.com için kimlik avı ve güvenlik kontrolü
“Drakebi: Most Popular Online Crypto Casino Based on Blockchain”
drakebi.com — Bilinen son aktif (HTTP 200). Marka kimliğine bürünme: Genericcrypto; Dolandırıcılık türü: Crypto Scam. Kanıt özeti: VT 14/91 (alphaMountain.ai, BitDefender, Chong Lua Dao, CyRadar, ESET); URLQuery 100 det.; URLScan malicious; GSB no flag; Spamhaus DBL_PHISH; BL 0; PD 100/100. Kayıt kuruluşu: Dominet (HK).
Özgün adli kaydı korumak için aşağıdaki ayrıntılı PhishDestroy AI analizi İngilizce bırakılmıştır.
Analysis of drakebi.com, first observed on July 23, 2026, indicates an active high‑risk phishing campaign targeting cryptocurrency users. The domain was registered on November 9, 2025 through Dominet (HK) Limited and resolves to the IP address 188.114.97.3, which is owned by AS13335 Cloudflare, Inc. and geolocated in the United States. The site delivers HTTP status 200 responses and presents a TLS certificate issued by Google Trust Services under the WE1 name, confirming that transport encryption is in place but not mitigating the underlying malicious intent. Page metadata reveals the title "Drakebi: Most Popular Online Crypto Casino Based on Blockchain," aligning with the classified scam type of a crypto scam and the identified phishing kit labeled as Gambler Scam.
Reputation services assign extremely low trust scores: Gridinsoft reports 1/100, while Scamadviser also records 1/100, and the domain appears on a single security blocklist. VirusTotal analysis shows that 15 of 95 scanned security vendors flag the domain as malicious, reinforcing the suspicion. Infrastructure fingerprints include Cloudflare Browser Insights and standard Cloudflare services, and the authoritative nameservers are dorthy.ns.cloudflare.com and elijah.ns.cloudflare.com.
The domain has been blocked by PhishDestroy, indicating that at least one anti‑phishing provider has taken mitigation action. Defenders should treat drakebi.com as a confirmed phishing source, enforce outbound filtering to block connections to its IP and associated Cloudflare hostnames, and incorporate the domain and its IP into indicator‑of‑compromise (IOC) feeds. Continuous monitoring of Cloudflare‑hosted assets and periodic re‑scanning with multiple vendors are advised to capture any evolution of the campaign.
Güvenlik Sinyalleri
Tehdit Müdahale Pipeline
Genel Engelleme Listesi Durumu
Kaydedilen görüntü
Etki Alanı Analizi
Teknik ayrıntılarDNS, SSL SAN’ları, zaman damgaları
ICANN OVERSIGHT
Akreditasyon ve RAA bağlamı
Akreditasyon ve RAA bağlamı
ICANN Parasını Aldı. Hesap Verebilirlik Gelmedi.
Bu gTLD için, yukarıdaki alan adı kayıt kuruluşu bir ICANN sözleşmesi kapsamında faaliyet gösterir. ICANN; kayıt, yenileme ve transferlerle bağlantılı yıllık, değişken ve işlem bazlı ücretler tahsil eder.
Akreditasyon: paraya çevrildi. Hesap verebilirlik: lütfen daha sonra tekrar kontrol edin.
Sonra sihir başlar: ICANN RAA §3.18'i yazar, alan adı kayıt kuruluşu kendi müşteri tabanındaki kötüye kullanımı soruşturur ve her katman bir başkasının harekete geçmesini beklerken mağdurlar kanıtları ücretsiz sunar. Bu, mağdurların kendilerini daha güvende hissetmelerini sağlıyorsa harika—demek ki fatura işe yaramış.
Kötüye Kullanım Bildirimi Geçmişi · 4 stored reports over 166 days · click to expand
-
Report #1 Feb 8, 2026 · 18:21 UTCPhishing Abuse Report: drakebi[.]comdomainabuse@service.aliyun.com
-
Report #2 ICANN CC 583h still active Mar 5, 2026 · 01:49 UTCESCALATION #2 (583h active): Phishing - drakebi[.]comdomainabuse@service.aliyun.com abuse@verisign-grs.com compliance@icann.org
-
Report #3 ICANN CC 616h still active Mar 6, 2026 · 10:40 UTCESCALATION #3 (616h active): Phishing - drakebi[.]comdomainabuse@service.aliyun.com abuse@verisign-grs.com compliance@icann.org
-
Report #4 ICANN CC 3974h still active Jul 24, 2026 · 14:00 UTCESCALATION #4 (3974h active): Phishing - drakebi[.]comabuse@verisign-grs.com compliance@icann.org
Teknolojiler · 2 identified
Performance monitoring tool that measures website speed from real users.
www.cloudflare.comWeb infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comVirusTotal Analizi
Arşivlenmiş Kanıtlar
Site Performans Analizi
Google PageSpeed Insights — mobile performance audit of drakebi.com · checked Mar 2, 2026
Kanıtlar ve Dış Raporlar
Bu Siteden Etkilendiniz mi?
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.
Bu Rapor Hakkında: drakebi.com
Bu rapor, PhishDestroy'un kullanabileceği en son saklanan kanıtları sunar. Kaynak zaman damgaları mümkün olan yerlerde gösterilir; Stok durumu ve satıcı kararları toplama sonrasında değişebilir.
Yakalanan site “Drakebi: Most Popular Online Crypto Casino Based on Blockchain” sayfa başlığını gösteriyordu ve Genericcrypto'nin kimliğine bürünüyor olabilir.
07.08.2026 itibarıyla drakebi.com, 14 güvenlik motorlarından tespitler aldı.
Bu listenin hatalı olduğunu düşünüyorsanız itirazda bulunmak. Metodolojimiz hakkında bilgi edinmek için SSS sayfası adresini ziyaret edin.
Herhangi Bir Alan Adını Kontrol Et
Saklanan engelleme listesi, WHOIS, DNS ve genel tarama kanıtlarını kullanarak tehdit analizi
Şimdi TaraOltalama Olayını Bildir
Şüpheli alan adlarını tehdit veritabanımıza bildirin — topluluğu koruyun
BildirCanlı Tehdit Akışı
Son kimlik avı raporları ve gözlemlenen kullanılabilirlik değişiklikleri
İzleGelişmelerden Haberdar Olun, Güvende Kalın
Canlı tehditleri izleyin veya bunun yanlış bir uyarı olduğunu düşünüyorsanız bu kayda itiraz edin