Notification and current-status evidence
The sent-report ledger records the first outgoing report at .
The recorded recipient is abuse@identitydigital.com.
The latest stored availability evidence still shows the domain reachable; 1 month has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
thalenequibridge[.]live
“Thalen EquiBridge | Official Platform for AI Assisted Trading”
thalenequibridge.live — Останній відомий активний (HTTP 200). Тип шахрайства: Generic Phishing. Зведення доказів: VirusTotal 16/91 (alphaMountain.ai, BitDefender, Cluster25, CRDF, ESET); Spamhaus DBL_PHISH; PhishDestroy score 100/100. Реєстратор: NiceNIC.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
This domain, thalenequibridge.live, is flagged as an active phishing site targeting users of AI-assisted trading platforms. Registered on June 2, 2026, through NICENIC INTERNATIONAL GROUP CO., LIMITED, the domain presents itself as the official platform for Thalen EquiBridge, a purported AI trading service. Infrastructure analysis reveals the site is hosted behind Cloudflare (AS13335) at IP address 188.114.96.3, a common tactic to obscure origin and evade takedowns. The domain currently resolves with a valid SSL certificate issued by Google Trust Services, which may lend a false sense of legitimacy to potential victims. The domain appears on at least one security blocklist and is flagged by 5 out of 95 security vendors on VirusTotal, indicating moderate but consistent detection. The HTTP status returns a 200 response, confirming the site is operational and serving content. The page title, 'Thalen EquiBridge | Official Platform for AI Assisted Trading,' directly mimics branding associated with legitimate trading platforms, a hallmark of credential harvesting or investment fraud schemes. The use of Cloudflare nameservers (arnold.ns.cloudflare.com and leah.ns.cloudflare.com) further complicates attribution, as the true hosting provider remains concealed. While the domain’s registration age is recent, its rapid inclusion on blocklists suggests either prior malicious activity or proactive detection based on infrastructure patterns. The Gridinsoft trust score of 0 out of 100 reinforces its classification as high-risk. Defenders should treat this domain as a confirmed phishing threat, particularly for users involved in cryptocurrency or AI-driven trading. Network-level blocking is recommended, along with monitoring for related domains registered under the same registrar or using identical nameserver configurations. No legitimate business purpose has been identified for this domain, and its continued operation indicates an ongoing campaign.
Розвіддані з мережевої безпеки Registrar context
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Збережений знімок
Аналітика доменів
Технічні деталіDNS, SAN-адреси SSL, мітки часу
ICANN OVERSIGHT
Акредитація та контекст RAA
Акредитація та контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Latest Classified Outcome 2026-08-14 02:38:17 UTC
Перехресна перевірка даних про загрози · source references
Аналіз VirusTotal
Докази та зовнішні звіти
PD-20260624-CCD73B Recipient: abuse@identitydigital.com Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога