Why this matters — ICANN RAA §3.18 obligation & victim-assistance
On PhishDestroy delivered an evidence-backed abuse report
(repeated 4 times, most recently ) to abuse@globaldomaingroup.com with the evidence stored for the case at that time.
More than 5 months later, the phishing infrastructure remains reachable
.
Under ICANN RAA §3.18 accredited registrars are contractually obliged to “take reasonable and prompt steps to investigate and respond appropriately to any reports of abuse.” Silence beyond 24 hours after a documented notification with verifiable evidence is not a timing issue — it is a policy decision to let the operation continue. PhishDestroy\'s position: where a registrar fails to act on clear evidence, the registrar has aligned itself with the operator of the scheme and bears co-responsibility for downstream harm caused to victims from the moment of notification onward.
Victim-assistance obligation. If Global Domain Group LLC doesn't consider the listed detections enough proof — that is interesting in itself, given the volume of independent vendor confirmations. But after 4 separate notifications over 5 months, with the operation still active, the registrar took no measurable action to mitigate the harm caused by their client. The reasonable next step is direct help to any identified victims — contact & payment-trail disclosure, abuse-thread transcripts, registrant data preservation — since the registrar chose, by inaction, to extend the window of damage.
xflippbase[.]cc
xflippbase.cc 网络钓鱼与安全检查
“Xflippbase: Most Popular Online Crypto Casino Based on Blockchain”
xflippbase.cc:VirusTotal 的 91 个引擎中有 15 个检出。查看 DNS、SSL、注册商、阻止列表和威胁情报。
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
PhishDestroy first observed xflippbase.cc on Feb 18, 2026. Evidence score: 100/100 (a triage score, not a probability).
Threat signals: 15 of 91 VirusTotal engines flagged the domain on Jul 26, 2026 at 03:35 UTC.
The endpoint responded with HTTP 403 on Aug 5, 2026 at 22:14 UTC, but access was restricted; content availability remains unconfirmed.
Other observations: No external blocklist matches were recorded in the snapshot from Aug 5, 2026 at 22:20 UTC. Google Safe Browsing recorded no flag on Mar 3, 2026 at 04:14 UTC. AlienVault OTX recorded 0 community pulse references on Mar 1, 2026 at 07:40 UTC. Spamhaus DBL recorded no positive result on Jul 14, 2026 at 10:31 UTC. URLScan captured the domain on Feb 18, 2026 at 16:40 UTC. Negative or missing results do not establish safety.
Context: registrar Global Domain Group LLC, IP address 188.114.96.3, apparent target Genericcrypto. Infrastructure details may have changed since collection.
This report summarizes time-bound observations, not a live guarantee. Avoid interacting with the domain; submit an appeal if the report is inaccurate.
威胁响应 Pipeline
公共封禁名单状态
滥用举报历史 · 4 stored reports over 33 days · click to expand
-
Report #1 ICANN CC 293h still active Mar 3, 2026 · 02:37 UTCESCALATION #2 (293h active): Phishing - xflippbase[.]ccabuse@globaldomaingroup.com abuse@verisign-grs.com compliance@icann.org
-
Report #2 ICANN CC 329h still active Mar 4, 2026 · 14:36 UTCESCALATION #3 (329h active): Phishing - xflippbase[.]ccabuse@globaldomaingroup.com abuse@verisign-grs.com compliance@icann.org
-
Report #3 ICANN CC 374h still active Mar 6, 2026 · 11:35 UTCESCALATION #4 (374h active): Phishing - xflippbase[.]ccabuse@globaldomaingroup.com abuse@verisign-grs.com compliance@icann.org
-
Report #5 ICANN CC 1082h still active Apr 5, 2026 · 02:07 UTCESCALATION #5 (1082h active): Phishing - xflippbase[.]ccabuse@globaldomaingroup.com abuse@verisign-grs.com compliance@icann.org
VirusTotal 分析
存档证据
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。