Notification and current-status evidence
The sent-report ledger records the first outgoing report at . It contains 2 outgoing records; the latest is dated . A report was sent to the recorded registrar; contact details remain in Domain Intelligence. The latest stored availability evidence still shows the domain reachable; 27 days has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
gaohux[.]com
Зведення доказів
Analysis of gaohux.com on July 22, 2026 confirms active phishing infrastructure targeting cryptocurrency users. The domain appears on three security blocklists—PhishDestroy, MetaMask, and SEAL—indicating broad industry recognition of malicious intent. Fourteen of ninety-five security vendors on VirusTotal flag the domain, reinforcing its classification as high-risk. No Safe Browsing or Open Threat Exchange (OTX) records were provided in the current intelligence, leaving real-time browser-level blocking status uncertain.
Infrastructure review reveals the domain is hosted on an IP address associated with low-reputation providers, though specific ASN and geolocation details remain undisclosed. The registrar and nameserver configuration have not been publicly linked to known bulletproof hosting, but the consistent blocklisting suggests evasive or disposable hosting practices. SSL certificate analysis was not included in the supplied data; defenders should verify certificate transparency logs for anomalies such as short validity periods or mismatched subject details. The exact content of the site is not yet analysed, though the presence on MetaMask’s blocklist strongly implies an attempt to impersonate crypto wallet login pages or distribute fraudulent wallet software.
No page title, phishing kit fingerprint, or targeted brand was provided, so the precise lure—whether a fake wallet recovery form, seed phrase theft page, or malicious dApp—cannot be confirmed. Defenders are advised to treat all interactions with gaohux.com as malicious and implement network-level blocking. Security teams should monitor for related domains using the same IP, nameserver, or SSL issuer patterns, as phishing operators frequently rotate infrastructure while maintaining core hosting providers.
Знімок надісланих доказів
- Надіслано
- Записи журналу
- 1
- ID справи
PD-1784033701-gaohux.com- PDF-файл
- PDF із доказами
Історія повідомлень 2
- Повідомлення № 2 ⚠️ ESCALATION #2 (420h active): Phishing - gaohux[.]com
- Повідомлення № 3 ⚠️ ESCALATION #3 (193h active): Phishing - gaohux[.]com
Data Coverage
Розвіддані з мережевої безпеки
Процес реагування на загрози Pipeline
Перевірка за блок-листами
10 зовнішніх джерел під наглядом · знімок від 11.08.2026
8 зовнішніх джерел під наглядом Збігів немає
Збережений знімок
Аналітика доменів
Технічні подробиціDNS, імена TLS і часові мітки
ICANN OVERSIGHT
Акредитація та контекст RAA
Акредитація та контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Аналіз VirusTotal
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога