Notification and current-status evidence
The sent-report ledger records the first outgoing report at .
The recorded recipient is abuse@identitydigital.com.
The latest stored availability evidence still shows the domain reachable; 1 month has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
info-spx6900[.]live
“Even geduld...”
info-spx6900.live — 未验证. 诈骗类型:Credential Phishing. 证据摘要: VirusTotal 4/91 (CRDF, Forcepoint ThreatSeeker, Gridinsoft, SOCRadar); URLQuery 2 alerts; 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 83/100. 注册商: NiceNIC.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
This domain, info-spx6900.live, has been identified as an active credential theft operation targeting users of financial platforms. Analysis indicates the site employs realistic login interfaces to harvest usernames, passwords, and multi-factor authentication codes. While no specific brand impersonation has been confirmed, the infrastructure and content patterns align with known credential harvesting campaigns observed in recent months. The domain shows no direct association with cryptocurrency drainer kits or wallet interception scripts at this time. Infrastructure analysis reveals the domain was registered on June 20, 2026, through NICENIC INTERNATIONAL GROUP CO., LIMITED, a registrar frequently utilized by threat actors for short-lived phishing domains. The site resolves to IP address 104.21.14.96, a Cloudflare-protected endpoint that obscures the true origin of the malicious content. As of the latest scan, the domain has received 0 detections out of 95 security engines on VirusTotal, indicating it remains undetected by most commercial security products. AlienVault OTX records the domain in a single threat intelligence pulse, suggesting limited but confirmed malicious activity. Google Safe Browsing currently lists the domain as unflagged, and no additional blocklist entries have been identified. Current status confirms the domain remains active and operational, serving credential theft content to unsuspecting visitors. No takedown actions have been observed, and the hosting infrastructure shows no signs of disruption. Users are advised to implement network-level blocking for the domain and associated IP address. Organizations should monitor for authentication attempts originating from this domain, particularly those targeting financial or corporate credentials. Given the domain's recent registration and low detection rate, continued evasion of security controls is likely until broader threat intelligence sharing occurs.
网络安全情报 Registrar context
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DNS4EU | info-spx6900.live |
malicious | Sinkholed |
| Hagezi Threat Feed | info-spx6900.live |
malicious | Sinkholed |
威胁响应 Pipeline
公共封禁名单状态
已保存的截图
域名情报
技术细节DNS、SSL SAN、时间戳
ICANN OVERSIGHT
认证和 RAA 背景
认证和 RAA 背景
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Latest Classified Outcome 2026-08-16 02:42:47 UTC
所用技术 · 2 identified
Cloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com 置信度 100%HTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 置信度 100%VirusTotal 分析
网站配置分析
证据与外部报告
PD-20260628-5CECD4 Recipient: abuse@identitydigital.com 您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。