Notification and current-status evidence
The sent-report ledger records the first outgoing report at . A report was sent to the recorded registrar; contact details remain in Domain Intelligence. The latest stored availability evidence still shows the domain reachable; 2 months has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
trevixprimeservices[.]com
“TrevixPrime-Service”
Kanıt özeti
This domain, trevixprimeservices.com, operates as a credential theft platform designed to harvest user login credentials through fraudulent financial service portals. The site presents itself under the title 'TrevixPrime-Service,' employing deceptive branding to trick visitors into submitting sensitive account information. Analysis indicates the infrastructure is optimized for credential capture, with technologies such as jQuery and Bootstrap facilitating dynamic form submissions and responsive design to enhance authenticity. The domain does not exhibit overt cryptocurrency drainer functionality but focuses on traditional credential theft, likely targeting banking or investment account access. Evidence supporting the malicious classification includes detection by 6 out of 95 security vendors on VirusTotal, alongside its presence on one security blocklist. The domain was registered through Dynadot Inc on June 01, 2026, an unusually future-dated creation that may indicate an attempt to evade age-based reputation filters. It resolves to the IP address 163.61.188.5 and employs a Let's Encrypt SSL certificate to simulate legitimacy. Additional technical indicators include the use of LiteSpeed, HTTP/3, and libraries like Select2 and FancyBox, which are consistent with phishing kit deployments designed to mimic legitimate service interfaces. Users who visited trevixprimeservices.com should immediately revoke any credentials entered on the site, particularly those tied to financial or email accounts. Monitor associated accounts for unauthorized transactions or login attempts, and enable multi-factor authentication where available. Network administrators should block the domain and its resolving IP (163.61.188.5) at the perimeter, and review logs for connections to this address. If browser sessions were active during the visit, clear cached data and run a full antivirus scan to detect potential secondary payloads or tracking scripts.
Gönderilen kanıt anlık görüntüsü
- Gönderildi
- Kayıt defteri kayıtları
- 1
- Vaka kimliği
PD-20260603-0812FF- Yakalanan sayfa başlığı
- TrevixPrime-Service
- PDF belgesi
- PDF kanıtı
Hukuki dayanak
Kanıtın tam metni
Policy Violations: Acceptable Use forbids illegal content; Spam & Abuse Policy prohibits phishing, fraud, malware; Dynadot may disable DNS and suspend domains
Applicable Laws: CFAA 18 U.S.C. §1030, Wire Fraud 18 U.S.C. §1343, CAN-SPAM Act
Data Coverage
Ağ Güvenliği İstihbaratı
Tehdit Müdahale Pipeline
Engelleme listesi kapsamı
10 izlenen harici kaynak · kayıtlı anlık görüntü 11.08.2026
Kaydedilen görüntü
Etki Alanı Analizi
Teknik ayrıntılarDNS, TLS adları ve zaman damgaları
ICANN OVERSIGHT
Akreditasyon ve RAA bağlamı
Akreditasyon ve RAA bağlamı
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Teknolojiler
8 yüksek güvenli teknoloji belirlendi
VirusTotal Analizi
Site Performans Analizi
Google PageSpeed Insights — mobile performance audit of trevixprimeservices.com · checked Jun 26, 2026
Bu Siteden Etkilendiniz mi?
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.
Herhangi Bir Alan Adını Kontrol Et
Saklanan engelleme listesi, WHOIS, DNS ve genel tarama kanıtlarını kullanarak tehdit analizi
Şimdi TaraOltalama Olayını Bildir
Şüpheli alan adlarını tehdit veritabanımıza bildirin — topluluğu koruyun
BildirCanlı Tehdit Akışı
Son kimlik avı raporları ve gözlemlenen kullanılabilirlik değişiklikleri
İzleGelişmelerden Haberdar Olun, Güvende Kalın
Canlı tehditleri izleyin veya bunun yanlış bir uyarı olduğunu düşünüyorsanız bu kayda itiraz edin