跳转到安全报告
Checked 2026年8月9日 Ref EF8B0775

MALICIOUS — HIGH

riowax[.]com

The domain riowax.com is a generic phishing site designed to deceive users through social media phishing tactics.

66/100 evidence score · High
VirusTotal
2/91
Blocklists
No stored match
可用性
最后已知的活跃状态 · HTTP 200
2026-03-24 11:58 UTC最后已知的活跃状态 · HTTP 200

Do not enter credentials, seed phrases, payment details, or personal information on this domain.

⚠️
该域名已被标记为恶意域名
安全引擎报告检测:2。 请格外小心——不要输入凭据或个人信息。
ABUSE NOTICE · 7D+ OPEN Outgoing abuse reports are recorded; the latest stored availability evidence still shows the domain reachable.
Notification and current-status evidence

The sent-report ledger records the first outgoing report at . It contains 6 outgoing records; the latest is dated . The recorded recipient is abuse@dynadot.com. The latest stored availability evidence still shows the domain reachable; 5 months has elapsed since the first outgoing report.

ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.

Elapsed since first report
5 months
Reports sent
6
Latest case ID
PD-1772502396-riowax.com
Current status
HTTP 200 at latest stored check
Jump to section
报告概览

riowax.com — 最后已知的活跃状态 (HTTP 200). 诈骗类型:Social Media Phishing. 证据摘要: VirusTotal 2/91 (Gridinsoft, SOCRadar); PhishDestroy score 66/100. 注册商: Dynadot.

为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。

Evidence Analysis

Ref EF8B0775

The domain riowax.com is a generic phishing site designed to deceive users through social media phishing tactics. It does not impersonate a specific brand or use a known drainer kit. As of the latest verification, riowax.com has been taken offline, reducing immediate risk to users, though its previous activity remains under investigation.

Technical indicators show that riowax.com had 0 of 95 VirusTotal vendors flagging it as malicious, and Google Safe Browsing did not list it as unsafe. The domain was registered through Dynadot LLC on March 04, 2026, and resolved to the IP address 23.35.29.9, hosted by Akamai Technologies in the US. It appeared on one security blocklist (PhishDestroy) and used an SSL certificate issued by Go Daddy Secure Certificate Authority - G2. The observed page title was 'riowax.com', and the site employed technologies such as PHP, Apache HTTP Server, jQuery, and Google Tag Manager. MX records pointed to 'park-mx.above.com', with nameservers at '5014.ns1.abovedomains.com' and '5014.ns2.abovedomains.com'.

Users who suspect they interacted with riowax.com should change any exposed credentials immediately, enable two-factor authentication on all accounts, and monitor for unauthorized activity. Report the domain to platforms like PhishTank, Google Safe Browsing, or local cybersecurity authorities to aid in broader mitigation efforts. If financial or cryptocurrency accounts were involved, review transaction histories and consider revoking any suspicious token approvals.

VirusTotal
VirusTotal
2 det.
URLScan
URLScan
TLS 证书
已过期或未验证
年龄
5 mo
观测状态
最后已知的活跃状态 200
PhishDestroy
DestroyList
已列入
Reports Sent
6
数据覆盖范围12 recorded checks
VirusTotal 2 / 91 URLQuery 未检查 PhishStats 未检查 OTX no community references CF雷达 scan completed URLScan capture 存储的报告 URLScan verdict 分析完成 DNS 阻断 14 已检查 — 未发现拦截 TLS 已过期或未验证 WHOIS 5 mo old 屏幕截图 外部截图 重定向链 未探查

威胁响应 Pipeline

发现
Checks
Reports
可用性
17/18
Initial Abuse Report (#1)
Sent to 1 abuse contact at Dynadot LLC with forensic evidence
abuse@dynadot.com
2026年2月26日
ICANN Escalation #2
Escalation #2 sent to 3 recipients including ICANN Compliance — follow-up record after a previous report
abuse@dynadot.comabuse@verisign-grs.comcompliance@icann.org
2026年3月3日
ICANN Escalation #3
Escalation #3 sent to 3 recipients including ICANN Compliance — follow-up record after multiple previous reports
abuse@dynadot.comabuse@verisign-grs.comcompliance@icann.org
2026年4月22日
ICANN Escalation #4
Escalation #4 sent to 3 recipients including ICANN Compliance — follow-up record after multiple previous reports
abuse@dynadot.comabuse@verisign-grs.comcompliance@icann.org
2026年4月26日
ICANN Escalation #5
Escalation #5 sent to 3 recipients including ICANN Compliance — follow-up record after multiple previous reports
abuse@dynadot.comabuse@verisign-grs.comcompliance@icann.org
2026年4月28日
ICANN Escalation #6
Escalation #6 sent to 3 recipients including ICANN Compliance — follow-up record after multiple previous reports
abuse@dynadot.comabuse@verisign-grs.comcompliance@icann.org
2026年5月5日
6 Reports Filed
6 report records were stored over 163 days; current observed status: 最后已知的活跃状态

公共封禁名单状态

已保存的截图

页面标题
riowax.com
TLS 证书
已过期或未验证 · 颁发者 Go Daddy Secure Certificate Authority - G2

域名情报

域名
URLScan Verdict 分析完成 score 0 report ↗
服务器 / ASN envoy · AS16625 AKAMAI-AS - Akamai Technologies, Inc., US
IP Context Akamai shared edge origin IP hidden Edge-IP 声誉不属于此域。
注册商 Dynadot US(US)
滥用举报联系方式abuse@dynadot.com
ICANN 注册管理机构ICANN官方认证注册商 →
IP 地址 23.35.29.9 CDN
地理位置US Sterling, US
网络AS16625 · Akamai Technologies, Inc.
源 IP 隐藏在 CDN 代理后面。边缘地址的反向 IP 结果包含不相关的租户;查找源头需要被动 DNS 或证书透明数据。
注册信息创建 2026年3月4日 (157d)
Elapsed Since First Report 10 days
统计口径 Raw elapsed time since the first stored abuse report. It is not a registrar response-time measurement. Latest observed status: 最后已知的活跃状态.
Minimum notice count 6 is the number of stored outgoing report records for this domain. It does not by itself prove acknowledgement or action by a recipient.
每份报告包含哪些内容 存储的传出报告记录可以参考当时可用的证据,例如供应商判决、注册数据、托管详细信息、分类或屏幕截图。此页面无法推断收件人交付、接收、确认或操作的确切有效负载。
ICANN RAA §3.18 The history below lists stored escalation records and timestamps. It does not by itself establish receipt, acknowledgement, compliance, or enforcement by any recipient.
HTTP 状态码200
技术细节DNS、SSL SAN、时间戳
首次发现2026年3月4日
DOM Analysisanalyzed 2026年7月11日score 48/100
IoC Extractionscanned 2026年8月1日0 wallet · 0 Telegram IoCs
域名服务器5014.ns2.abovedomains.com
MX Records10 park-mx.above.com
Case ID
ICANN OVERSIGHT

认证和 RAA 背景

Registrar accreditation and DNS abuse obligations

For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.

Accreditation is a contract, not a safety certification.

RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.

Accountability draft 不会自动发送任何内容。
滥用举报历史 · 6 stored reports over 68 days · click to expand
This timeline is built from stored outgoing report records. It documents timestamps and listed recipients, but does not by itself prove delivery, acknowledgement, or recipient action.
6 abuse reports filed over 163 days — latest observed status: 最后已知的活跃状态
The records name Dynadot LLC as a recipient or subject. ICANN Compliance appears in the recipient field for at least one record.
6
reports
163
days
ICANN CC
  1. Report #1 Feb 26, 2026 · 22:39 UTC
    Phishing Abuse Report: riowax[.]com
    abuse@dynadot.com
  2. Report #2 ICANN CC 99h still active Mar 3, 2026 · 01:46 UTC
    ESCALATION #2 (99h active): Phishing - riowax[.]com
    abuse@dynadot.com abuse@verisign-grs.com compliance@icann.org
  3. Report #3 ICANN CC 1314h still active Apr 22, 2026 · 20:15 UTC
    ESCALATION #3 (1314h active): Phishing - riowax[.]com
    abuse@dynadot.com abuse@verisign-grs.com compliance@icann.org
  4. Report #4 ICANN CC 1407h still active Apr 26, 2026 · 17:16 UTC
    ESCALATION #4 (1407h active): Phishing - riowax[.]com
    abuse@dynadot.com abuse@verisign-grs.com compliance@icann.org
  5. Report #5 ICANN CC 1456h still active Apr 28, 2026 · 18:20 UTC
    ESCALATION #5 (1456h active): Phishing - riowax[.]com
    abuse@dynadot.com abuse@verisign-grs.com compliance@icann.org
  6. Report #6 ICANN CC 1614h still active May 5, 2026 · 08:36 UTC
    ESCALATION #6 (1614h active): Phishing - riowax[.]com
    abuse@dynadot.com abuse@verisign-grs.com compliance@icann.org
Record scope: the timeline documents outgoing records stored by PhishDestroy. Delivery, acknowledgement, and subsequent action require separate recipient or infrastructure evidence.
所用技术 · 7 identified
PHP
Programming languages

Server-side scripting language designed for web development.

Apache HTTP Server
Web servers

Most widely used open-source HTTP server software.

jQuery UI

Legacy JavaScript library — DOM manipulation and AJAX helpers. Still widely present on older sites.

J
jQuery CDN

Legacy JavaScript library — DOM manipulation and AJAX helpers. Still widely present on older sites.

jQuery
JavaScript libraries

Fast, small JavaScript library simplifying HTML manipulation, event handling, and Ajax.

Google Tag Manager
Tag managers

Tag management system for deploying marketing and analytics tags.

tagmanager.google.com
Contentsquare
Detected via Cloudflare Radar · Wappalyzer engine
举报此域名 提交证据,帮助保护他人

VirusTotal 分析

2 / 91 安全供应商标记了该域
View on VT
Last analyzed First positive detection Previous stored snapshot: 0 detections
Gridinsoft
SOCRadar
网站性能分析

Google PageSpeed Insights — mobile performance audit of riowax.com · checked Mar 5, 2026

48
Poor
Performance
FCP
2.94s
First Contentful Paint
LCP
22.68s
Largest Contentful Paint
CLS
0
Cumulative Layout Shift
TBT
551ms
Total Blocking Time
SI
8.18s
Speed Index
Powered by Google PageSpeed Insights · Mobile strategy · Scores: 90-100 Good 50-89 Needs Work 0-49 Poor
证据与外部报告Independent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
If credentials were compromised, report immediately. Do not engage with recovery scammers.

如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。

欧洲刑警组织
查找您所在欧盟国家/地区的官方报告渠道
National police directory
警惕“数据恢复”诈骗! 犯罪分子可能会冒充调查员、律师或追债员再次联系受害者。 请勿支付预付费用或共享凭证。 了解有关康复欺诈的更多信息 →

向当地主管部门报告

选择您所在的国家/地区以获取 官方网络犯罪联系人创建投诉草稿 →

97个国家目录
AI辅助草稿——事件详细信息由AI提供商处理 自行审核并提交
嵌入此报告Read-only HTML widget
HTML · IFRAME

嵌入此报告

在您的网站或博客上分享此威胁情报

embed.html
<iframe
  src="https://phishdestroy.io/zh/embed/domain/riowax.com"
  title="PhishDestroy threat report for riowax.com"
  width="100%" height="320"
  loading="lazy"
  referrerpolicy="no-referrer"
  sandbox="allow-same-origin allow-popups allow-popups-to-escape-sandbox"
  style="border:0;border-radius:12px;max-width:100%"
></iframe>

一封无比真诚的感谢信

讽刺信件草稿生成器

收件方
费用背景

这是讽刺性草稿。费用数字均为估算;我们并不声称这些费用可被准确归因于此域名。