Notification and current-status evidence
The sent-report ledger records the first outgoing report at .
The recorded recipient is abuse@dynadot.com.
The latest stored availability evidence still shows the domain reachable; 6 months has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
provenancefdn[.]com
Перевірка домену provenancefdn.com на фішинг і безпеку
“Provenance: The Leading Blockchain for Digital Real-World Asset Tokenization”
provenancefdn.com — Неперевірений. Тип шахрайства: Crypto Scam. Зведення доказів: VirusTotal 2/93 (Gridinsoft, SOCRadar); PhishDestroy score 71/100. Реєстратор: Dynadot.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
The domain provenancefdn.com is under investigation for crypto blockchain impersonation, specifically targeting users of the Provenance blockchain platform. Analysis indicates the site masquerades as an official portal for digital real-world asset tokenization, a core function of the legitimate Provenance network. As of the latest assessment, the domain has been taken offline, though prior activity suggests it was operational for malicious purposes. Infrastructure analysis reveals the domain was registered through Dynadot LLC on February 21, 2026, an anomalous creation date likely intended to evade detection by appearing futuristic. It resolves to the IP address 104.21.29.6 and employs Cloudflare for hosting, a common tactic to obscure origin servers and evade geoblocking. The site utilized Plesk, PHP, RequireJS, and Prototype, alongside HTTP/3 for performance optimization. Despite its technical sophistication, the domain holds a Gridinsoft trust score of 0/100 and appears on three security blocklists, including MetaMask, SEAL, and PhishDestroy. Notably, VirusTotal reports 0/95 detections, indicating low initial visibility among antivirus vendors despite its presence on specialized threat feeds. The SSL certificate is issued by Google Trust Services, providing a veneer of legitimacy while failing to mitigate the underlying malicious intent. Current evidence suggests this domain was designed to deceive users into interacting with fraudulent smart contracts or wallet-draining mechanisms, a hallmark of crypto-focused phishing operations. Given its offline status, the immediate threat is mitigated, but the infrastructure may resurface under a different domain or IP configuration. Organizations and individuals are advised to monitor for similar impersonation attempts, particularly those leveraging blockchain terminology or branding. Network defenders should block the IP 104.21.29.6 and domain provenancefdn.com at the perimeter, while users should verify the authenticity of any Provenance-related communications through official channels. Security teams are encouraged to review logs for prior connections to this domain and investigate potential exposure to crypto wallet-draining schemes.
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Збережений знімок
Аналітика доменів
Технічні деталіDNS, SAN-адреси SSL, мітки часу
ICANN OVERSIGHT
Акредитація та контекст RAA
Акредитація та контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Технології · 6 identified
Plesk is a web hosting and server data centre automation software with a control panel developed for Linux and Windows-based retail hosting service providers.
www.plesk.com 100% впевненостіRequireJS is a JavaScript library and file loader which manages the dependencies between JavaScript files and in modular programming.
requirejs.org 100% впевненостіPrototype is a JavaScript Framework that aims to ease development of web applications.
www.prototypejs.org 100% впевненостіCloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com 100% впевненостіHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100% впевненостіАналіз VirusTotal
Архівні докази
Аналіз продуктивності сайту
Google PageSpeed Insights — mobile performance audit of provenancefdn.com · checked Jun 27, 2026
Докази та зовнішні звіти
PD-20260130-29ADDC Recipient: abuse@dynadot.com Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога