MALICIOUS — HIGH
riowax[.]com
The domain riowax.com is a generic phishing site designed to deceive users through social media phishing tactics.
- VirusTotal
- 2/91
- Blocklists
- No stored match
- 可用性
- 最后已知的活跃状态 · HTTP 200
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Notification and current-status evidence
The sent-report ledger records the first outgoing report at .
It contains 6 outgoing records; the latest is dated . The recorded recipient is abuse@dynadot.com.
The latest stored availability evidence still shows the domain reachable; 5 months has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
Jump to section
riowax.com — 最后已知的活跃状态 (HTTP 200). 诈骗类型:Social Media Phishing. 证据摘要: VirusTotal 2/91 (Gridinsoft, SOCRadar); PhishDestroy score 66/100. 注册商: Dynadot.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
Evidence Analysis
The domain riowax.com is a generic phishing site designed to deceive users through social media phishing tactics. It does not impersonate a specific brand or use a known drainer kit. As of the latest verification, riowax.com has been taken offline, reducing immediate risk to users, though its previous activity remains under investigation.
Technical indicators show that riowax.com had 0 of 95 VirusTotal vendors flagging it as malicious, and Google Safe Browsing did not list it as unsafe. The domain was registered through Dynadot LLC on March 04, 2026, and resolved to the IP address 23.35.29.9, hosted by Akamai Technologies in the US. It appeared on one security blocklist (PhishDestroy) and used an SSL certificate issued by Go Daddy Secure Certificate Authority - G2. The observed page title was 'riowax.com', and the site employed technologies such as PHP, Apache HTTP Server, jQuery, and Google Tag Manager. MX records pointed to 'park-mx.above.com', with nameservers at '5014.ns1.abovedomains.com' and '5014.ns2.abovedomains.com'.
Users who suspect they interacted with riowax.com should change any exposed credentials immediately, enable two-factor authentication on all accounts, and monitor for unauthorized activity. Report the domain to platforms like PhishTank, Google Safe Browsing, or local cybersecurity authorities to aid in broader mitigation efforts. If financial or cryptocurrency accounts were involved, review transaction histories and consider revoking any suspicious token approvals.
数据覆盖范围12 recorded checks
威胁响应 Pipeline
公共封禁名单状态
已保存的截图
域名情报
技术细节DNS、SSL SAN、时间戳
ICANN OVERSIGHT
认证和 RAA 背景
认证和 RAA 背景
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
滥用举报历史 · 6 stored reports over 68 days · click to expand
-
Report #1 Feb 26, 2026 · 22:39 UTCPhishing Abuse Report: riowax[.]comabuse@dynadot.com
-
Report #2 ICANN CC 99h still active Mar 3, 2026 · 01:46 UTCESCALATION #2 (99h active): Phishing - riowax[.]comabuse@dynadot.com abuse@verisign-grs.com compliance@icann.org
-
Report #3 ICANN CC 1314h still active Apr 22, 2026 · 20:15 UTCESCALATION #3 (1314h active): Phishing - riowax[.]comabuse@dynadot.com abuse@verisign-grs.com compliance@icann.org
-
Report #4 ICANN CC 1407h still active Apr 26, 2026 · 17:16 UTCESCALATION #4 (1407h active): Phishing - riowax[.]comabuse@dynadot.com abuse@verisign-grs.com compliance@icann.org
-
Report #5 ICANN CC 1456h still active Apr 28, 2026 · 18:20 UTCESCALATION #5 (1456h active): Phishing - riowax[.]comabuse@dynadot.com abuse@verisign-grs.com compliance@icann.org
-
Report #6 ICANN CC 1614h still active May 5, 2026 · 08:36 UTCESCALATION #6 (1614h active): Phishing - riowax[.]comabuse@dynadot.com abuse@verisign-grs.com compliance@icann.org
所用技术 · 7 identified
Server-side scripting language designed for web development.
Most widely used open-source HTTP server software.
Legacy JavaScript library — DOM manipulation and AJAX helpers. Still widely present on older sites.
Legacy JavaScript library — DOM manipulation and AJAX helpers. Still widely present on older sites.
Fast, small JavaScript library simplifying HTML manipulation, event handling, and Ajax.
Tag management system for deploying marketing and analytics tags.
tagmanager.google.comVirusTotal 分析
网站性能分析
Google PageSpeed Insights — mobile performance audit of riowax.com · checked Mar 5, 2026
证据与外部报告Independent lookups and source reports
PD-1772502396-riowax.com Recipient: abuse@dynadot.com Victim safety and official reportingImmediate actions and verified reporting channels
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。