Güvenlik raporuna geç
⚠️
Bu alan adı, zararlı olarak işaretlenmiştir
Güvenlik motorları bir algılama bildiriyor: 3. Çok dikkatli olun — kimlik bilgilerini veya kişisel bilgileri girmeyin.
ABUSE NOTICE · 7D+ OPEN Outgoing abuse reports are recorded; the latest stored availability evidence still shows the domain reachable.
Notification and current-status evidence

The sent-report ledger records the first outgoing report at . The recorded recipient is domainabuse@tucows.com. The latest stored availability evidence still shows the domain reachable; 4 months has elapsed since the first outgoing report.

ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.

Elapsed since first report
4 months
Reports sent
1
Latest case ID
PD-20260329-A53F43
Current status
Observed active at latest stored check
Etki alanı güvenliği ve tehdit istihbaratı

rainbow-recovery[.]org

“Rainbow Recovery”

Tehdit kararı Yüksek 65/100 kanıt puanı
Kullanılabilirlik Doğrulanmamış Mevcut erişilebilirlik doğrulanmadı
VirusTotal algılamaları: 3/91 Dolandırıcılık türü: Wallet/Seed Phishing
29.03.2026 1 Report Sent
Rapor özeti

rainbow-recovery.org — Doğrulanmamış. Dolandırıcılık türü: Wallet/seed Phishing. Kanıt özeti: VirusTotal 3/91 (CRDF, Gridinsoft, SOCRadar); PhishDestroy score 65/100. Kayıt kuruluşu: Tucows.

Özgün adli kaydı korumak için aşağıdaki ayrıntılı PhishDestroy AI analizi İngilizce bırakılmıştır.

Kanıt özeti
YÜKSEK
Ref
A6887AE5
Puan
65/100

PhishDestroy identifies rainbow-recovery.org as an active impersonation site targeting individuals seeking recovery services. This domain mimics legitimate recovery organizations to harvest sensitive personal information such as names, contact details, and financial data. The site is designed to appear credible, using a Let's Encrypt SSL certificate to create the illusion of trustworthiness. Visitors who enter any information risk identity theft, financial fraud, or being targeted by follow-up scams.

This domain was flagged by PhishDestroy after VirusTotal recorded 0 out of 95 security engines detecting the threat as of the latest scan. The domain resolves to IP address 198.185.159.145 and was registered through TUCOWS.COM, CO. on May 27, 2021. The site’s recent creation date and low detection rate suggest it is a newly deployed threat designed to evade early-stage security filters. The use of a legitimate SSL certificate further lowers user suspicion, increasing the likelihood of successful data theft.

If you visited rainbow-recovery.org, do not enter any personal or financial information. Immediately cease all interaction with the site and close your browser. Run a full antivirus scan on your device to check for any malware or unauthorized access. Report the domain to your organization’s security team or to PhishDestroy if you suspect exposure. Avoid clicking on any links or downloading files from the site. Stay vigilant for follow-up phishing attempts, as scammers often use stolen data to launch targeted attacks. Always verify the legitimacy of recovery services through official channels before sharing sensitive information.

VirusTotal
VirusTotal
3 det.
DNS Security
1/12
URLScan
URLScan
TLS sertifikası
Let's Encrypt
Yaş
5 mo
Gözlemlenen durum
Doğrulanmamış
PhishDestroy
DestroyList
Listede
Reports Sent
1
Veri kapsamı VirusTotal 3 / 91 URLQuery checked — no detections recorded PhishStats checked — no match recorded OTX no community references CF Radarı scan completed URLScan capture saklanan rapor URLScan verdict Analiz tamamlandı DNS engellemeleri 1/12 TLS valid certificate, 89d WHOIS 5 mo old Ekran görüntüsü 3 captures · 3 sources Yönlendirme zinciri araştırılmadı
Ağ Güvenliği İstihbaratı
DNS Provider Blocks 1 / 12
Brand Rainbow

Tehdit Müdahale Pipeline

Keşif
Checks
Reports
Kullanılabilirlik
11/12
Sent Report Recorded
Stored sent-report record for registrar Tucows Domains Inc., hosting provider, 2 abuse contacts
abuse-network@squarespace.comdomainabuse@tucows.com
29.03.2026

Genel Engelleme Listesi Durumu

Kaydedilen görüntü

Sayfa başlığı
Rainbow Recovery
TLS sertifikası
Valid transport encryption · Düzenleyen Let's Encrypt · valid for 89 days

Etki Alanı Analizi

Alan adı
URLScan Verdict Analiz tamamlandı score 0 report ↗
Sunucu / ASN Squarespace · AS53831 Squarespace, Inc.
IP itibarı abuse score 32/100 26 reports checked 13.08.2026
IP adresi 198.185.159.145 US
Coğrafi konumUS New York, US
AS53831 · Squarespace, Inc.
KayıtOluşturuldu 29.03.2026 (137d)
Elapsed Since First Report 42h
Neyi ölçüyoruz Raw elapsed time since the first stored abuse report. It is not a registrar response-time measurement. Latest observed status: Doğrulanmamış.
Her raporun içeriği Saklanan giden rapor kayıtları, satıcı kararları, kayıt verileri, barındırma ayrıntıları, sınıflandırmalar veya ekran görüntüleri gibi o sırada mevcut olan kanıtlara referans verebilir. Bu sayfa, teslim edilen yükün, alındığının, onaylandığının veya alıcının yaptığı eylemin tam olarak ne olduğu konusunda bir sonuç çıkarmaz.
Teknik ayrıntılarDNS, SSL SAN’ları, zaman damgaları
İlk Kez Tespit Edildi29.03.2026
IoC Extractionscanned 29.07.20260 wallet · 0 Telegram IoCs
Submitted URLhttp://rainbow-recovery.org/
Ad sunucularıns04.squarespacedns.com
TLS Fingerprint
TLS Observationvalid from 29.03.2026scanned 30.03.2026
Case ID
ICANN OVERSIGHT

Akreditasyon ve RAA bağlamı

Registrar accreditation and DNS abuse obligations

For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.

Accreditation is a contract, not a safety certification.

RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.

Accountability draft Hiçbir şey otomatik olarak gönderilmez.
Teknolojiler · 4 identified
S
Squarespace Commerce

Website builder and hosting platform.

Squarespace

Website builder and hosting platform.

Stimulus
HSTS
Güvenlik

HTTP Strict Transport Security — forces browsers to use HTTPS connections only.

Detected via Cloudflare Radar · Wappalyzer engine
Bu Alan Adını Bildir Kanıt sunun ve başkalarını korumaya yardımcı olun

VirusTotal Analizi

3 / 91 güvenlik sağlayıcıları bu alanı işaretledi
View on VT
Last analyzed First positive detection Previous stored snapshot: 0 detections
CRDF
Gridinsoft
SOCRadar
Site Performans Analizi

Google PageSpeed Insights — mobile performance audit of rainbow-recovery.org · checked Mar 29, 2026

74
Needs Work
Performance
FCP
3.16s
First Contentful Paint
LCP
4.37s
Largest Contentful Paint
CLS
0.03
Cumulative Layout Shift
TBT
217ms
Total Blocking Time
SI
3.7s
Speed Index
Powered by Google PageSpeed Insights · Mobile strategy · Scores: 90-100 Good 50-89 Needs Work 0-49 Poor

Kanıtlar ve Dış Raporlar

Submitted Evidence Snapshot
Sent: Ledger records: 1 Case ID: PD-20260329-A53F43 Recipient: domainabuse@tucows.com
Page title stored with report: Rainbow Recovery
URLScan evidence VirusTotal evidence URLQuery evidence Screenshot 506.0 KB

Bu Siteden Etkilendiniz mi?

If credentials were compromised, report immediately. Do not engage with recovery scammers.

Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.

Europol
AB ülkeniz için resmi raporlama kanalını bulun
National police directory
Kurtarma dolandırıcılarına dikkat edin! Suçlular, araştırmacı, avukat veya kurtarma görevlisi gibi davranarak mağdurlarla tekrar iletişime geçebilir. Peşin ücret ödemeyin veya kimlik bilgilerinizi paylaşmayın. Geri ödeme dolandırıcılığı hakkında daha fazla bilgi edinin →

Yerel Yetkililere Bildirin

resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.

97 ülke rehberi
Yapay zeka destekli taslak — olay ayrıntıları yapay zeka sağlayıcısı tarafından işlenir Kendiniz inceleyin ve gönderin

Herhangi Bir Alan Adını Kontrol Et

Saklanan engelleme listesi, WHOIS, DNS ve genel tarama kanıtlarını kullanarak tehdit analizi

Şimdi Tara

Oltalama Olayını Bildir

Şüpheli alan adlarını tehdit veritabanımıza bildirin — topluluğu koruyun

Bildir

Canlı Tehdit Akışı

Son kimlik avı raporları ve gözlemlenen kullanılabilirlik değişiklikleri

İzle

Gelişmelerden Haberdar Olun, Güvende Kalın

Canlı tehditleri izleyin veya bunun yanlış bir uyarı olduğunu düşünüyorsanız bu kayda itiraz edin

Canlı Tehdit Akışı Bu İlanı İtiraz Et
HTML · IFRAME

Bu Raporu Yerleştir

Bu tehdit bilgisini web sitenizde veya blogunuzda paylaşın

embed.html
<iframe
  src="https://phishdestroy.io/tr/embed/domain/rainbow-recovery.org"
  title="PhishDestroy threat report for rainbow-recovery.org"
  width="100%" height="320"
  loading="lazy"
  referrerpolicy="no-referrer"
  sandbox="allow-same-origin allow-popups allow-popups-to-escape-sandbox"
  style="border:0;border-radius:12px;max-width:100%"
></iframe>

Çok İçten Bir Teşekkür Mektubu

Hicivli taslak oluşturucu

Alıcı
Ücret bağlamı

Hicivli taslak. Ücret rakamları tahminidir; bu alan adına kesin olarak atfedildikleri iddia edilmez.