Request For Review

What is the name of the domain?

ikuyo.top

What is the issue you’re encountering

I received an email from your company on June 2nd, concerning a malware attack associated with my website. The email indicated that the software communicated/spread via the link hxxps://ikuyo[.]top/wp-content/uploads/2025/05/Emby.apk. Upon investigation, I confirmed this file was indeed present in my website server’s directory. Immediately after receiving your notification, I took action by removing the file targeted by this link. Subsequent testing confirmed that the file/malware is no longer accessible for download via this URL, and the URL itself has been removed. However, as of today, the status in the first report link provided in your email (Issue ID 70594810 - Netcraft Malware URL Information) still indicates the issue remains unresolved. Conversely, the second report link (Netcraft Incident Response) shows the issue as resolved. As of today, June 6th, my domain name resolution (ikuyo.top) has been suspended by my registrar, confirming the problem persists. I have thoroughly verified that both the file and the link have been definitively removed. I kindly request that your company re-investigate this matter. If the issue has indeed been resolved, please update the abuse detection status in your report to “Resolved” or withdraw the report. If the problem is still being detected, I may require further technical support or information to help identify and resolve the underlying issue.

Was the site working with SSL prior to adding it to Cloudflare?

Yes

What is the current SSL/TLS setting?

Full

Looks like you’re missing DNS records under the DNS tab of Cloudflare dashboard for your zone? :thinking: Did you cross-checked and pointed your ikuyo.top to an IP address of the server where the Website conent is present and hosted? :thinking:

;QUESTION
ikuyo.top. IN A
;ANSWER
Record not found!

Helpful articles:

Hello fritex,thank you for your reply!I originally thought there might be an issue with Cloudflare, so I temporarily deleted the domain, but it remained unresolvable. I then realized that my registrar had suspended the domain’s resolution. Even after re-adding the domain, resolution still fails. Below is a screenshot of my DNS resolution records – these are identical to the records I had before deleting the domain.


What can I do now?

Thank you for feedback.

Could you please cross-check the nameservers from the Overview page and your Nameservers at your Domain registrar interface? :thinking:

If you’ve re-added your domain and it already contained some other Cloudflare nameservers (obviously assigned to your CF account since before), could be you’v got a new pair (new set) of Cloudflare nameservers and that you need to check and change them at your domain registrar to make it work again.

Which ones have you got at Overview page for ikuyo.top zone? :thinking:
Which ones are domain nameservers at your domain registrar?

Could you double-check if you’ve actually changed your domain nameservers instead of creating and adding them as NS type of the DNS records?

Should be:

Name Server: jakub.ns.cloudflare.com
Name Server: kate.ns.cloudflare.com

Looks like domain status is still serverHold, meaning you’re not able to make any changes until you resolve this with your registrar first:
Domain Status: serverHold https://icann.org/epp#serverHold

I’ve checked the nameservers at my registrar; a screenshot is provided below:

I believe they are correctly configured.

I’ve submitted a nameserver audit request. However, I had previously requested a nameserver audit as well. Could this delay be because my domain is under serverHold status?

I’ve contacted my registrar regarding lifting the serverHold. Their response indicated that resolution depends on the abuse report at https://incident.netcraft.com/b57c57971afb/ being marked as resolved.

Given this situation:

  1. Should I simply wait for the nameserver audit to complete?
  2. Or are there additional steps I can take to expedite this?

I appreciate your guidance on this matter!

On the Cloudflare side, the Overview page displays the following:

That is the correct thing to do!

In that case, you will need to contact Netcraft, and find a way to get the issue resolved, together with Netcraft.

Once you have resolved the issue with Netcraft, then you will need to return to your registrar again, to attempt to get the serverHold status removed.

That will be something you need to take up with your registrar and/or Netcraft.

As long as your domain name has the serverHold status, it will be like your domain name doesn’t exist.

Cloudflare won’t be able to do anything here.

3 Likes

This topic was automatically closed 2 days after the last reply. New replies are no longer allowed.