MALICIOUS — CRITICAL
aispa.uk — Web3 Crypto Drainer Phishing Investigation Report
aispa[.]
This domain, aispa.uk, is confirmed to host a Web3 crypto drainer phishing operation targeting users of decentralized applications and cryptocurrency wallets.
- VirusTotal
- 3/91
- Blocklists
- 1 · ScamSniffer
- التوفر
- مغطى بعباءة · يمكن الوصول إليه · HTTP 404
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
aispa.uk — مغطى بعباءة · يمكن الوصول إليه (HTTP 404). نوع الاحتيال: Crypto Drainer. ملخص الأدلة: VirusTotal 3/91 (CRDF, Gridinsoft, SOCRadar); 1 external blocklist match (ScamSniffer); cloaking observed; PhishDestroy score 81/100. مسجّل النطاق: Cloudflare.
يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.
Evidence Analysis
This domain, aispa.uk, is confirmed to host a Web3 crypto drainer phishing operation targeting users of decentralized applications and cryptocurrency wallets. The site presents itself as 'AISPA — The AI Security Layer for the Next Era of Web3,' a fabricated security service designed to deceive users into connecting their wallets via malicious smart contract interactions. Once connected, the embedded scripts execute unauthorized transactions, draining funds from the victim’s wallet without consent. The attack vector leverages social engineering tactics, exploiting trust in AI and Web3 security branding to facilitate financial theft. Analysis indicates the domain was registered on April 14, 2026, through Cloudflare, Inc., and resolves to the IP address 216.150.1.1. It is flagged by 3 out of 95 security vendors on VirusTotal, with detections including phishing and malicious content classifications. The domain appears on two independent security blocklists and is actively blocked by PhishDestroy and ScamSniffer. Infrastructure analysis reveals the use of Node.js, React, and Next.js frameworks, alongside Vercel hosting and a Let's Encrypt SSL certificate, which are commonly observed in both legitimate and malicious Web3 applications. The Gridinsoft trust score of 0/100 further corroborates the domain’s malicious intent. Users who visited aispa.uk or interacted with its content are advised to immediately revoke any connected wallet permissions via their wallet interface or a blockchain explorer. All connected devices should undergo a full antivirus scan to detect potential secondary infections. If cryptocurrency transactions were initiated, victims should report the incident to their wallet provider and relevant blockchain analytics platforms for transaction tracing. Additionally, monitor all linked accounts for unauthorized access or transactions, and consider migrating assets to a new wallet if compromise is confirmed. Future interactions with Web3 applications should be restricted to verified, audited platforms with established reputations.
Stored source results
Recorded verdicts and infrastructure observations for this domain.
نطاق تغطية البيانات12 recorded checks
مسار الاستجابة للتهديدات Pipeline
حالة قوائم الحظر العامة
التقنيات · 6 identified
Node.js is an open-source, cross-platform, JavaScript runtime environment that executes JavaScript code outside a web browser.
nodejs.org ثقة 100٪React is an open-source JavaScript library for building user interfaces or UI components.
reactjs.org ثقة 100٪Next.js is a React framework for developing single page Javascript applications.
nextjs.org ثقة 100٪HTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org ثقة 100٪تحليل VirusTotal
تحليل أداء الموقع
Google PageSpeed Insights — mobile performance audit of aispa.uk · checked Jun 26, 2026
الأدلة والتقارير الخارجيةIndependent lookups and source reports
PD-20260504-AD5781 Recipient: abuse@vercel.com Victim safety and official reportingImmediate actions and verified reporting channels
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.