Notification and current-status evidence
The sent-report ledger records the first outgoing report at .
The recorded recipient is abuse@tonic.to.
The latest stored availability evidence still shows the domain reachable; 2 months has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
narcos24[.]to
“Вы не робот?”
narcos24.to — 未验证. 诈骗类型:Generic Phishing. 证据摘要: VirusTotal 6/91 (alphaMountain.ai, CRDF, Forcepoint ThreatSeeker, Fortinet, Gridinsoft); PhishDestroy score 71/100. 注册商: Government of Kingdom ….
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
PhishDestroy identifies narcos24.to as a confirmed generic phishing site, now taken offline. The domain posed as a security verification page with the Russian-language title "Вы не робот?" ("Are you not a robot?"), a common trick to steal credentials or deliver malware. Although no specific brand was impersonated, its generic nature made it a versatile threat for widespread scams.
Technical analysis reveals troubling indicators. VirusTotal flagged the domain by 2 of 95 security vendors, confirming malicious reputation. It appears on one security blocklist and was registered through the Government of Kingdom of Tonga, a registrar often exploited for fraudulent domains. The domain was created on April 1, 2026, and resolved to IP address 91.206.71.106. Its SSL certificate was issued by Google Trust Services (WE1), lending a false sense of legitimacy. The page title directly matched known phishing lures, and the domain's recent creation further underscores its suspicious nature.
Although narcos24.to is currently offline, users who encountered it should exercise caution. If any information was entered on the fake verification page, change passwords immediately and enable two-factor authentication on affected accounts. Run a full antivirus scan and monitor for identity theft signs. PhishDestroy advises avoiding any interaction with such domains and reporting them to security authorities. Staying vigilant against unexpected CAPTCHA-like prompts is crucial, as they often precede data theft. This domain's removal highlights the ongoing battle against phishing infrastructure, but users remain the last line of defense.
威胁响应 Pipeline
公共封禁名单状态
所用技术 · 1 identified
Cloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com 置信度 100%VirusTotal 分析
网站性能分析
Google PageSpeed Insights — mobile performance audit of narcos24.to · checked May 20, 2026
证据与外部报告
PD-20260520-81B89D Recipient: abuse@tonic.to 您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。