VirusTotal
1 / 89
The sent-report ledger records the first outgoing report at .
The recorded recipient is abuse+registry@porkbun.com.
The latest stored availability evidence still shows the domain reachable; 8 months has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
thorwap.finance — Доступно · доступ обмежено (HTTP 403). Тип шахрайства: Impersonation. Зведення доказів: VirusTotal 1/89 (Gridinsoft); URLQuery 2 alerts; PhishDestroy score 81/100. Реєстратор: Porkbun.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
1 / 89
2 threat-system alerts
Повідомити23 community references
Повідомитиprovider verdict: clean
Повідомитизбережений звіт
Повідомити Аналіз завершено
ПовідомитиChecked; no threat flag recorded
Повідомити| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| YARAhub by abuse.ch | thorwap.finance/after.js |
malware | Detects file containing Telegram Bot API |
| OpenDNS | api.ceooflidare.icu |
phishing | Phishing Block |
The domain thorwap.finance, associated with a generic phishing operation, has a high threat score of 75/100 and is currently down. It has been flagged as malicious by 4 out of 95 security vendors, including Gridinsoft and SOCRadar, and is listed on one public blocklist, though Google Safe Browsing has not flagged it.
Registered with Porkbun LLC, the domain was created on February 21, 2026, and was first detected on February 3, 2026. The hosting IP is 172.67.182.116. The operational status and detection metrics indicate a significant threat level, warranting immediate action. Block the domain at the perimeter and submit a report to the registrar's abuse desk.
Збережені дані спостережень за взаємодією веб-сканера та браузера для цього хоста, а також перевірка відбитків у режимі реального часу для систем розподілу трафіку типу «Кейтаро».
cloudflareПримітка щодо сканера: cloudflare_challenge: raw=cf_challenge; http=403; via=https_proxy; server=cloudflare
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Репутація Edge-IP не пов’язана з цим доменом.
annalise.ns.cloudflare.comLocation describes the IP network.
ed2fef6b910d9b4d5f325f333b021ce7ef91c9f4afcd95df8a9b97d9b5e2875cSaved certificate metadata. Certificate dates without a timezone are shown as stored. Transport encryption does not establish that the site is trustworthy.
Google PageSpeed Insights — mobile performance audit of thorwap.finance · checked Apr 28, 2026
13 recorded events. These records describe collected evidence, outgoing notifications and publication; they do not confirm a complete investigation or a takedown.
We scan suspicious URLs, inspect public results and send evidence through the appropriate abuse-reporting channels. The dated events above show what is recorded for this domain. The directory below explains the wider workflow.
Capture the rendered page, requests and visible infrastructure.
Compare the available engine results and retain the analysis timestamp.
Check whether Google currently lists the URL as unsafe.
Inspect a public scan and its recorded network and classification data.
Look for indicator references and related community intelligence.
Compare archived captures and preserve historical context.
Look for matching indicators and associated threat records.
Inspect certificate records and related hostnames.
Compare security resolver responses and record observed blocking.
Inspect the public DNS, TLS, HTTP and technology surface.
Security services used for scanning, reputation checks and reporting are listed below. A service being listed is not evidence that it received, accepted or acted on this particular domain. Recorded submissions appear in the notification history above.
Повідомив 1 учасник спільноти; уперше помічено 03.02.2026
PD-20260203-A9E920 Recipient: abuse+registry@porkbun.com Policy Violations: Acceptable Use Policy (AUP): The domain thorwap.finance is engaged in phishing activities, which are explicitly prohibited under your AUP. This constitutes a direct violation of the policy's stipulation against illegal activities and fraud. Terms of Service (TOS): The continued operation of this domain violates your TOS, which reserves the right to suspend or terminate services for any activities that facilitate deception or fraud. Applicable Laws (Unknown): Computer Fraud and Abuse Act (CFAA): This U.S. federal law prohibits unauthorized access to computers and networks, which is relevant as phishing schemes often involve unauthorized data access. Wire Fraud Statute (18 U.S.C. § 1343): This law criminalizes schemes to defraud individuals or entities via electronic communications, encompassing phishing activities. Anti-Phishing Act of 2004: This legislation specifically targets phishing schemes and imposes penalties for those who engage in such deceptive practices. Regulatory Note: Failure to take immediate action against thorwap.finance may expose your organization to legal liability and regulatory scrutiny. Compliance with your AUP and TOS is essential to mitigate risks associated with hosting malicious content.
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Template-based draft · optional AI wording assistance requires separate consent
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразДодавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиОстанні звіти про фішинг і помічені зміни доступності
ВідстежуватиСлідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога