dexlow[.]top
“REWARD Portal v2 --- Latest Web3 Wallets”
ملخص الأدلة
Analysis of dexlow.top indicates a brand-impersonation campaign targeting Trust Wallet users. The site was registered on September 28, 2025 through NiceNIC International Group Co., Limited and is currently taken offline. DNS resolution points to IP address 209.94.90.1, which belongs to AS40680 owned by Protocol Labs in the United States. The domain is served by Cloudflare name servers coen.ns.cloudflare.com and tia.ns.cloudflare.com, suggesting the attacker leveraged Cloudflare for DNS and potential DDoS mitigation.
No SSL certificate is present, meaning the site operated over HTTP only, a typical characteristic of low‑confidence phishing kits. The page title returned from the server reads "REWARD Portal v2 --- Latest Web3 Wallets," aligning with the declared scam type of wallet/seed phishing. Gridinsoft assigns a trust score of 0 out of 100, confirming the domain as highly suspicious. VirusTotal reports three detections out of ninety‑five scanned vendors, and the domain appears on at least one external blocklist.
PhishDestroy has already added the domain to its block list, reinforcing the consensus that it is malicious. Uncertainty remains regarding the content hosted before takedown, as no visual or HTML snapshot is available, and it is unclear whether additional infrastructure (e.g., command‑and‑control servers) is linked to the same IP. Defenders should block DNS resolution to 209.94.90.1, add dexlow.top to web‑filter and endpoint denial lists, monitor for similar Cloudflare‑based domains employing the same page title pattern, and enforce strict verification of Trust Wallet communications in user‑education programs.
Data Coverage
استخبارات أمن الشبكات
مسار الاستجابة للتهديدات Pipeline
تغطية قوائم الحظر
١٠ مصادر خارجية مراقبة · لقطة محفوظة 11/08/2026
المخطط الزمني للاكتشاف
-
Cloudflare Radar
تم حفظ فحص Cloudflare Radar · فتح الفحص
لقطة محفوظة
معلومات النطاق
التفاصيل التقنيةDNS وأسماء TLS والطوابع الزمنية
ICANN OVERSIGHT
الاعتماد وسياق RAA
الاعتماد وسياق RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
تحليل VirusTotal
هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب