MALICIOUS — CRITICAL
فحص التصيد والأمان للنطاق midnight-od.com
midnight-od[.]
PhishDestroy identifies midnight-od.com as a malicious domain actively distributing a crypto drainer disguised as the Midnight Token Generation Event (TGE) platform.
- VirusTotal
- 16/91
- Blocklists
- 2 · MetaMask, SEAL
- التوفر
- آخر نشاط معروف · HTTP 200
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Notification and current-status evidence
The sent-report ledger records the first outgoing report at .
The recorded recipient is abuse@rtmnetworks.net.
The latest stored availability evidence still shows the domain reachable; 4 months has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
Jump to section
midnight-od.com — آخر نشاط معروف (HTTP 200). نوع الاحتيال: Fake Airdrop. ملخص الأدلة: VirusTotal 16/91 (ADMINUSLabs, ChainPatrol, alphaMountain.ai, BitDefender, Chong Lua Dao); URLQuery 4 alerts; 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 100/100. مسجّل النطاق: TuringSign.
يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.
Evidence Analysis
PhishDestroy identifies midnight-od.com as a malicious domain actively distributing a crypto drainer disguised as the Midnight Token Generation Event (TGE) platform. The site mimics legitimate cryptocurrency project pages to trick users into connecting wallets and signing malicious transactions, resulting in fund theft. The threat actor leverages urgency and familiarity with the Midnight brand to deceive visitors into authorizing unauthorized transactions, making this a high-risk impersonation attack targeting crypto investors. This domain was flagged by 9 out of 95 VirusTotal security vendors, indicating widespread detection of its malicious nature. Registered through TuringSign Inc. d/b/a Cosmotown on February 27, 2026, midnight-od.com has already been blocked by major security platforms including MetaMask and SEAL, and appears on two independent blocklists. The use of a Let’s Encrypt SSL certificate adds a false sense of legitimacy, further complicating user detection. Users who visited midnight-od.com should immediately disconnect their wallets from any connected sites, revoke any unauthorized token approvals, and scan their systems for malware. Never interact with unsolicited links or websites claiming to offer exclusive TGE access. Report any suspicious activity to your wallet provider and relevant cybersecurity teams. Stay vigilant against brand impersonation scams in the crypto space.
Stored source results
Recorded verdicts and infrastructure observations for this domain.
نطاق تغطية البيانات13 recorded checks
استخبارات أمن الشبكات
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Private YARA rules | midnight-od.com/index_files/base.js.download |
audit | Hunting_JS_WebAssembly |
| Cloudflare DNS | midnight-od.com |
malicious | Sinkholed |
| DNS4EU | midnight-od.com |
malicious | Sinkholed |
| Quad9 DNS | midnight-od.com |
malicious | Sinkholed |
مسار الاستجابة للتهديدات Pipeline
حالة قوائم الحظر العامة
لقطة محفوظة
معلومات النطاق
التفاصيل الفنيةDNS، أسماء المجال البديلة (SAN) في بروتوكول SSL، الطوابع الزمنية
ICANN OVERSIGHT
الاعتماد وسياق RAA
الاعتماد وسياق RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
تحليل VirusTotal
تحليل أداء الموقع
Google PageSpeed Insights — mobile performance audit of midnight-od.com · checked Apr 6, 2026
تحليل إعدادات الموقع
الأدلة والتقارير الخارجيةIndependent lookups and source reports
PD-20260406-972198 Recipient: abuse@rtmnetworks.net Victim safety and official reportingImmediate actions and verified reporting channels
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.