Notification and current-status evidence
The sent-report ledger records the first outgoing report at .
The recorded recipient is complaint@gname.com.
The latest stored availability evidence still shows the domain reachable; 1 month has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
lvvas[.]net
Перевірка домену lvvas.net на фішинг і безпеку
“lvvas”
lvvas.net — Останній відомий активний (HTTP 200). Тип шахрайства: Generic Phishing. Зведення доказів: VirusTotal 5/91 (alphaMountain.ai, CRDF, Forcepoint ThreatSeeker, Gridinsoft, SOCRadar); URLQuery 1 alert; 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 83/100. Реєстратор: Gname.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
Analysis of lvvas.net confirms its classification as an active generic phishing domain, operational since February 25, 2026. The domain resolves to 172.67.148.109, hosted on Cloudflare's infrastructure (AS13335), a common pattern observed in phishing campaigns leveraging content delivery networks to obscure origin servers. The site presents a minimal page title 'lvvas' with no additional branding or context, a tactic frequently employed to avoid immediate detection by automated crawlers while maintaining functionality for targeted phishing links. Infrastructure indicators reveal the domain was registered through Gname.com Pte. Ltd., a registrar historically associated with higher volumes of malicious domains. The SSL certificate, issued by Let's Encrypt (YE1), provides encryption but does not validate legitimacy, as phishing sites routinely use free certificates to appear secure. Detection by multiple security blocklists—including PhishDestroy, MetaMask, and SEAL—along with its presence in two AlienVault OTX threat intelligence pulses, corroborates its malicious classification. Only one of ninety-five security vendors on VirusTotal currently flags the domain, suggesting either recent activation or evasion techniques targeting specific detection mechanisms. The domain's nameservers (lady.ns.cloudflare.com and zod.ns.cloudflare.com) are consistent with Cloudflare-protected phishing sites, which often rotate DNS configurations to complicate takedown efforts. While the exact phishing kit or targeted brand remains unconfirmed, the site's generic presentation aligns with credential-harvesting campaigns where victims are redirected or tricked into submitting login details. Defenders should treat this domain as high-risk and prioritize blocking at the DNS or network layer. Monitoring for subdomains or newly associated IP addresses is recommended, as phishing operators frequently shift infrastructure to maintain persistence.
Розвіддані з мережевої безпеки
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DigiCert UltraDNS | oss.awsossli.com |
malicious | Sinkholed |
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Збережений знімок
Аналітика доменів
Технічні деталіDNS, SAN-адреси SSL, мітки часу
ICANN OVERSIGHT
Акредитація та контекст RAA
Акредитація та контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Аналіз VirusTotal
Докази та зовнішні звіти
PD-20260623-F9ECC0 Recipient: complaint@gname.com Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога