dexscreener[.]com[.]co
“Bloom Sniper”
dexscreener.com.co — المحتوى غير متوفر. انتحال العلامة التجارية: Across; نوع الاحتيال: Wallet/seed Phishing. ملخص الأدلة: VirusTotal 1/95 (SOCRadar); PhishDestroy score 65/100. مسجّل النطاق: PDR.
يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.
The domain dexscreener.com.co was observed hosting a site with the page title “Bloom Sniper”. Infrastructure analysis shows the domain resolves to the IPv4 address 193.233.198.34, which is allocated to AS209207 operated by Digital Hosting Provider LLC in Germany. The domain is served without an SSL/TLS certificate, exposing all HTTP traffic to interception. Registration data indicates the domain was created on 10 April 2025 through PDR Ltd. d/b/a PublicDomainRegistry.com, and it is configured with Beget nameservers (ns1.beget.com, ns1.beget.pro, ns2.beget.com, ns2.beget.pro).
The site is currently offline, but historical data confirm it was used for a wallet/seed phishing campaign that impersonates the brand “across”. VirusTotal scans flagged the domain in one of ninety‑five security vendors, and the Gridinsoft trust score is 0 / 100, reflecting extreme risk. The domain appears on a single security blocklist and is actively blocked by PhishDestroy. While the page title and hosting details are concrete, the exact phishing payload, credential‑capture mechanisms, and any associated command‑and‑control infrastructure have not been publicly disclosed.
Defenders should add the domain and its resolved IP address to blocklists, enforce HTTPS‑only policies, and monitor outbound traffic for connections to the German host. Continuous re‑inspection of the domain’s DNS records is advised, as the lack of SSL and low trust score suggest the possibility of future re‑activation. Incident response teams should treat any credentials or seed phrases submitted to the site as compromised, reset affected wallets, and advise users to verify legitimate brand communications before providing sensitive information.
مسار الاستجابة للتهديدات Pipeline
حالة قوائم الحظر العامة
تحليل VirusTotal
الأدلة والتقارير الخارجية
هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب