Notification and current-status evidence
The sent-report ledger records the first outgoing report at .
The recorded recipient is abuse@dynadot.com.
The latest stored availability evidence still shows the domain reachable; 3 months has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
zargatesfi[.]com
zargatesfi.com 网络钓鱼与安全检查
“ZarGates”
zargatesfi.com — 未验证. 诈骗类型:Generic Phishing. 证据摘要: VirusTotal 4/94 (alphaMountain.ai, CRDF, Gridinsoft, SOCRadar); URLQuery 1 alert; 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 78/100. 注册商: Dynadot.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
Analysis of zargatesfi.com indicates a high‑risk phishing operation that remains active as of 12 July 2026. The domain was registered on 16 April 2026 through Dynadot Inc and resolves to Cloudflare‑hosted IP 104.21.68.231 located in Canada. SSL is provided by Let’s Encrypt (E7). HTTP responses return status 521, suggesting the origin server is refusing connections, a pattern often observed with malicious front‑ends behind Cloudflare. The page title returned by the site is “ZarGates,” but no further content has been captured, leaving the exact phishing payload undefined. Infrastructure profiling shows the site runs on Plesk with PHP and loads Google Hosted Libraries and Google Font API, while Cloudflare Browser Insights and HTTP/3 are active, confirming modern delivery mechanisms. Threat intelligence flags are robust: four of ninety‑four VirusTotal scanners have flagged the domain, it appears on three public blocklists, and it is listed in twenty‑two AlienVault OTX pulses. Defensive services such as PhishDestroy, MetaMask, and SEAL have already blocked the domain, and Gridinsoft assigns a trust score of 0 / 100. Given the convergence of registration recency, active blocking, multiple vendor detections, and the presence in numerous threat pulses, security teams should add the domain to DNS and URL filtering blocks, monitor outbound traffic for connections to 104.21.68.231, and keep watch for any related sub‑domains that may share the same Cloudflare infrastructure. Further investigation of the site’s landing page content is recommended to confirm the specific credential‑harvesting technique employed.
网络安全情报
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Private YARA rules | www.youtube.com/s/player/b174a5bb/player_embed_es6.vflset/en_us/base.js |
audit | Hunting_JS_WebAssembly |
威胁响应 Pipeline
公共封禁名单状态
已保存的截图
域名情报
技术细节DNS、SSL SAN、时间戳
ICANN OVERSIGHT
认证和 RAA 背景
认证和 RAA 背景
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
所用技术 · 7 identified
Server-side scripting language designed for web development.
Performance monitoring tool that measures website speed from real users.
www.cloudflare.comWeb infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
VirusTotal 分析
网站性能分析
Google PageSpeed Insights — mobile performance audit of zargatesfi.com · checked Jul 12, 2026
证据与外部报告
PD-20260416-003426 Recipient: abuse@dynadot.com 您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。