Notification and current-status evidence
The sent-report ledger records the first outgoing report at .
The recorded recipient is abuse@clausweb.ro.
The latest stored availability evidence still shows the domain reachable; 12 days has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
mikka-style[.]ro
“Error 404 - Not found”
mikka-style.ro — 未验证. 证据摘要: VirusTotal 13/91 (alphaMountain.ai, BitDefender, Cluster25, CRDF, ESET); URLQuery 2 alerts; PhishDestroy score 95/100. 注册商: Claus Web SRL.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
On August 04, 2026 the domain mikka-style.ro was observed as an active generic phishing infrastructure. The domain is currently listed as blocked by the PhishDestroy sinkhole, indicating that traffic to the host has been intercepted and redirected. VirusTotal analysis shows that 2 of 91 scanned security vendors flagged the domain, which suggests a low but non‑zero detection rate among AV engines.
Additionally, the domain appears on a single external security blocklist, reinforcing the view that it is being used for malicious purposes. No public WHOIS data, IP address, hosting provider, or SSL certificate details have been disclosed in the available intelligence, and the page title or any associated brand references have not been captured. Consequently, the exact target brand or the phishing kit employed cannot be confirmed at this time.
The limited detection footprint combined with the presence on a blocklist and sinkhole indicates that the infrastructure is likely being leveraged for credential harvesting or similar credential‑stealing campaigns, consistent with the generic phishing classification. Defenders should add mikka-style.ro to domain blocklists across perimeter and endpoint security solutions, monitor DNS queries for look‑ups to the domain, and consider feeding the indicator into threat‑intelligence platforms to improve collective detection. Continuous re‑evaluation is advised, as additional telemetry such as hosting IP, TLS fingerprints, or page content may emerge and refine the risk assessment.
网络安全情报
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| YARAhub by abuse.ch | mikka-style.ro/event/adobe.html |
malware | Detects file containing Telegram Bot API |
| DNS4EU | mikka-style.ro |
malicious | Sinkholed |
威胁响应 Pipeline
公共封禁名单状态
所用技术 · 1 identified
HTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 置信度 100%VirusTotal 分析
证据与外部报告
PD-20260804-BAE8D5 Recipient: abuse@clausweb.ro 您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。