Notification and current-status evidence
The sent-report ledger records the first outgoing report at .
The recorded recipient is abuse@dynadot.com.
The latest stored availability evidence still shows the domain reachable; 5 months has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
event-nomina[.]xyz
“event-nomina.xyz | 504: Gateway time-out”
event-nomina.xyz — Doğrulanmamış. Dolandırıcılık türü: Generic Phishing. Kanıt özeti: VirusTotal 12/91 (alphaMountain.ai, BitDefender, Chong Lua Dao, CRDF, ESET); URLQuery 1 alert; PhishDestroy score 98/100. Kayıt kuruluşu: Dynadot.
Özgün adli kaydı korumak için aşağıdaki ayrıntılı PhishDestroy AI analizi İngilizce bırakılmıştır.
This domain, event-nomina.xyz, is actively flagged as a high-risk phishing endpoint with a current HTTP 504 Gateway Time-out response. Registered on March 13, 2026, through Dynadot LLC, the domain resolves to IP address 104.21.56.133, which is protected by Cloudflare infrastructure. Analysis indicates the use of HTTP/3 and a Let's Encrypt SSL certificate, common in both legitimate and malicious deployments. The domain appears on two security blocklists and has been included in 23 threat intelligence pulses on a major open-source threat exchange platform, suggesting recurring malicious activity. Security vendors have detected this domain with moderate consistency, as 13 out of 95 engines on a widely used malware scanning service flagged it as malicious. The domain remains active despite the 504 error, which may indicate temporary hosting issues or deliberate evasion tactics. The registration details and infrastructure choices align with patterns observed in phishing campaigns targeting financial or payroll-related lures, though the exact payload or deception method remains unconfirmed due to the current gateway timeout. Defenders should treat this domain as hostile and prioritize blocking it at the network level. The IP address 104.21.56.133 should be monitored for additional malicious domains, as Cloudflare-protected IPs are frequently reused in phishing operations. Given the domain's presence on multiple blocklists and its inclusion in numerous threat intelligence reports, organizations should review logs for any prior connections to event-nomina.xyz or its associated IP. If internal systems or users have interacted with this domain, immediate investigation for credential theft or malware delivery is recommended.
Ağ Güvenliği İstihbaratı
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DNS4EU | event-nomina.xyz |
malicious | Sinkholed |
Tehdit Müdahale Pipeline
Genel Engelleme Listesi Durumu
Kaydedilen görüntü
Etki Alanı Analizi
Teknik ayrıntılarDNS, SSL SAN’ları, zaman damgaları
ICANN OVERSIGHT
Akreditasyon ve RAA bağlamı
Akreditasyon ve RAA bağlamı
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Teknolojiler · 2 identified
Web infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
VirusTotal Analizi
Kanıtlar ve Dış Raporlar
PD-20260313-9911C7 Recipient: abuse@dynadot.com Bu Siteden Etkilendiniz mi?
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.
Herhangi Bir Alan Adını Kontrol Et
Saklanan engelleme listesi, WHOIS, DNS ve genel tarama kanıtlarını kullanarak tehdit analizi
Şimdi TaraOltalama Olayını Bildir
Şüpheli alan adlarını tehdit veritabanımıza bildirin — topluluğu koruyun
BildirCanlı Tehdit Akışı
Son kimlik avı raporları ve gözlemlenen kullanılabilirlik değişiklikleri
İzleGelişmelerden Haberdar Olun, Güvende Kalın
Canlı tehditleri izleyin veya bunun yanlış bir uyarı olduğunu düşünüyorsanız bu kayda itiraz edin