maicapital1[.]com
“Crypto.com Onchain: A Self-custodial Wallet from Crypto.com”
ملخص الأدلة
This domain, maicapital1.com, is flagged for brand impersonation targeting users of the Across protocol and Crypto.com platform. Analysis indicates the site presents itself as a legitimate self-custodial wallet under the title 'Crypto.com Onchain: A Self-custodial Wallet from Crypto.com,' designed to deceive victims into disclosing wallet credentials or transferring cryptocurrency to attacker-controlled addresses. No explicit drainer kit signatures were identified in initial scans, though the infrastructure and page content strongly suggest credential harvesting or asset diversion intent. Infrastructure analysis reveals the domain was registered on January 9, 2025, through Gname.com Pte. Ltd. and resolves to the IP address 104.19.223.17. Detection metrics show 0/95 detections on VirusTotal, indicating no antivirus engines currently flag the domain as malicious. However, it appears on two security blocklists, including PhishDestroy and OISD. The site employs a Google Trust Services SSL certificate and utilizes multiple technologies, including Node.js, React, Next.js, and Amazon Web Services, which may facilitate rapid deployment and evasion of detection. As of the latest assessment, maicapital1.com has been taken offline, reducing immediate exposure risk. However, the domain remains registered, and the infrastructure could be reactivated or repurposed. Users who interacted with the site prior to takedown should assume potential credential or asset compromise and take immediate remedial action, including revoking wallet permissions, rotating passwords, and monitoring for unauthorized transactions. Network-level blocking of the IP 104.19.223.17 is recommended for proactive defense.
Data Coverage
مؤشرات الأمان
مسار الاستجابة للتهديدات Pipeline
تغطية قوائم الحظر
١٠ مصادر خارجية مراقبة · لقطة محفوظة 12/08/2026
المخطط الزمني للاكتشاف
-
VirusTotal
2 ← 1
-
VirusTotal
2 ← 0
لقطة محفوظة
معلومات النطاق
التفاصيل التقنيةDNS وأسماء TLS والطوابع الزمنية
ICANN OVERSIGHT
الاعتماد وسياق RAA
الاعتماد وسياق RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
التقنيات
حُدّدت ٢١ تقنية عالية الثقة
تحليل VirusTotal
الأدلة المؤرشفة
هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب