app[.]dexscreerer[.]net
“www.app.dexscreerer.net”
ملخص الأدلة
PhishDestroy identifies app.dexscreerer.net as an active cryptocurrency wallet drainer site, masquerading under the guise of a legitimate DeFi tool. The domain leverages a spoofed branding strategy to mimic credible platforms, thereby tricking users into authorizing malicious transactions. Initial telemetry indicates this infrastructure is designed to siphon digital assets from unwitting victims, with the threat actor employing deceptive UI/UX patterns to facilitate unauthorized fund transfers. The seed identifier 8b6e8a has been linked to this campaign, suggesting a coordinated effort to deploy drainer kits against unsuspecting cryptocurrency users.
This domain exhibits several concerning technical attributes that warrant immediate scrutiny. VirusTotal currently scores it at 1/95 detections, indicating a lack of signature-based detection despite its malicious intent. The domain resolves to an IP address associated with hosting providers known for harboring fraudulent infrastructures. Registration details reveal a creation date within the last 12 months, suggesting a relatively new but rapidly operationalized threat. The registrar remains unconfirmed in public databases, while the SSL certificate is issued by Google Trust Services, a tactic often used to lend false legitimacy to phishing domains. Additionally, this domain has not yet been flagged by Google Safe Browsing or major threat intelligence blocklists, amplifying its potential for propagation.
As of the latest assessment, app.dexscreerer.net remains active, with no signs of takedown or remediation by hosting providers. The absence of detection underscores the sophistication of this campaign, which evades conventional security measures. Immediate actions for defenders include blocking the domain at the network perimeter and updating DNS sinkholes to prevent resolution. Users are strongly advised to verify URLs before interacting with DeFi platforms, enable transaction simulation tools where available, and report suspicious domains to threat intelligence platforms. The residual risk posed by this domain remains high, given its unchecked activity and the likelihood of further victimization. Proactive monitoring and threat hunting are critical to mitigating potential losses.
Data Coverage
استخبارات أمن الشبكات
مسار الاستجابة للتهديدات Pipeline
تغطية قوائم الحظر
١٠ مصادر خارجية مراقبة · لقطة محفوظة 12/08/2026
أدلة النتيجة المحفوظة
النتيجة وإسناد الإزالة
- النتيجة
held- التوفر
unreachable- السبب
registrar_client_hold- الجهة الفاعلة
- NICENIC INTERNATIONAL GROUP CO., LIMITED
- الآلية
client_hold- درجة الثقة
- 95%
- أول رصد
- أحدث رصد
وقت التعطل التقديري
الوقت حتى تعذر الوصول: 0 hSHA-256 للدليل fbab9fb7508f
المخطط الزمني للاكتشاف
-
التوفر
أول قيمة محفوظة: DNS غير نشط
f93a11f87e4d -
التوفر
DNS غير نشط ← غير معروف
4e1339ecd601 -
التوفر
غير معروف ← DNS غير نشط
f688b4712f2d -
التوفر
DNS غير نشط ← محتجز
faa3dd051c8b -
التوفر
محتجز ← DNS غير نشط
f52d526b76a1 -
التوفر
DNS غير نشط ← غير معروف
3ecbb218af01 -
التوفر
غير معروف ← محتجز
34d080cc7a60 -
التوفر
محتجز ← غير معروف
a5c66649b5fb -
التوفر
غير معروف ← DNS غير نشط
6dfe9145995c -
التوفر
DNS غير نشط ← محتجز
0ee31c3e5e68
عرض الكل (9)
-
التوفر
محتجز ← DNS غير نشط
641ed81dc4d5 -
التوفر
DNS غير نشط ← غير معروف
82e86c4e2a3f -
التوفر
غير معروف ← محتجز
f4fe94ab2a4e -
التوفر
محتجز ← غير معروف
6d8640f91a33 -
التوفر
غير معروف ← DNS غير نشط
d0b7046e8c2f -
التوفر
DNS غير نشط ← محتجز
2981f09516df -
التوفر
محتجز ← DNS غير نشط
ca9ed662b468 -
التوفر
DNS غير نشط ← غير معروف
1f627b22c4c7 -
التوفر
غير معروف ← محتجز
fbab9fb7508f
بلاغات المجتمع
أبلغ عنه عضو واحد في المجتمع؛ شوهد أول مرة في 28/04/2026
- البلاغات المحفوظة
- 1
- عناوين URL الفريدة المبلغ عنها
- 1
معلومات النطاق
التفاصيل التقنيةDNS وأسماء TLS والطوابع الزمنية
ICANN OVERSIGHT
Registration: dexscreerer.net
الاعتماد وسياق RAA
الاعتماد وسياق RAA
Registrar accreditation and DNS abuse obligations
For the registrable domain dexscreerer.net behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
التقنيات
حُدّدَت تقنيتان عاليتا الثقة
تحليل VirusTotal
هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب