n8n[.]consensys-digital[.]cloud
“n8n.io - Workflow Automation”
ملخص الأدلة
The domain n8n.consensys-digital.cloud was registered on February 21, 2026 through Hostinger Operations, UAB and is delegated to the parking nameservers ns1.dns-parking.com and ns2.dns-parking.com. DNS resolution points to the IPv4 address 168.231.79.222, which belongs to AS47583 Hostinger International Limited and is geolocated in Great Britain. No TLS certificate is presented for the host, indicating that HTTPS is not available and that any traffic to the site would be unencrypted. The site’s HTTP response returned a page title of "n8n.io - Workflow Automation," matching the legitimate n8n brand, suggesting an attempt to masquerade as the authentic service.
VirusTotal scans have recorded three positive detections out of ninety‑five security vendors, providing independent confirmation that the domain is associated with malicious activity. The domain is currently listed on three public blocklists—PhishDestroy, MetaMask, and SEAL—and has been flagged by additional security blocklists, reinforcing its reputation as a phishing vector. The host is presently taken offline, which may be the result of takedown actions or automated mitigation.
While the page content has not been examined directly, the combination of brand‑matching page title, lack of TLS, host‑based detection, and blocklist listings constitute strong evidence of a generic phishing operation aimed at credential harvesting for n8n.io users. Defenders should continue to block the domain at network perimeter and DNS layers, monitor for any re‑appearance of the host on the same IP range, and advise users to verify URLs before entering credentials. Ongoing surveillance of the associated IP address and related AS is recommended to detect potential repurposing for further malicious campaigns.
لقطة الأدلة المرسلة
- أُرسل
- سجلات الدفتر
- 1
- معرّف القضية
PD-20260218-124405- عنوان الصفحة الملتقطة
- n8n.io - Workflow Automation
- ملف PDF
- دليل PDF
الأساس القانوني
النص الكامل للدليل
Section 3.1 of the Acceptable Use Policy: The domain n8n.consensys-digital.cloud is being used for phishing activities, which constitutes a clear violation of the prohibition against illegal activities and deception.
Section 5.2 of the Terms of Service: The registrar reserves the right to suspend or terminate services for any violations, including those related to fraud and phishing, which are evident in the activities associated with this domain.
Applicable Laws (Unknown):
Computer Fraud and Abuse Act (CFAA) - 18 U.S.C. § 1030: This federal law prohibits unauthorized access to computers and networks, including activities that involve phishing.
Wire Fraud Statute - 18 U.S.C. § 1343: This law addresses fraudulent schemes that involve electronic communications, which is applicable to phishing activities that deceive individuals for financial gain.
CAN-SPAM Act - 15 U.S.C. § 7701: This act regulates commercial email and prohibits deceptive practices, including those associated with phishing.
Regulatory Note: Failure to take appropriate action against this domain may result in regulatory scrutiny and potential liability under applicable laws. Immediate suspension is advised to mitigate risks associated with non-compliance.
Data Coverage
استخبارات أمن الشبكات
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Private YARA rules | n8n.consensys-digital.cloud/assets/worker-civwfg3a.js |
audit | Hunting_JS_WebAssembly |
| Quad9 DNS | n8n.consensys-digital.cloud |
malicious | Sinkholed |
مسار الاستجابة للتهديدات Pipeline
تغطية قوائم الحظر
١٠ مصادر خارجية مراقبة · لقطة محفوظة 13/08/2026
المخطط الزمني للاكتشاف
-
Cloudflare Radar
تم حفظ فحص Cloudflare Radar · فتح الفحص
لقطة محفوظة
معلومات النطاق
التفاصيل التقنيةDNS وأسماء TLS والطوابع الزمنية
ICANN OVERSIGHT
Registration: consensys-digital.cloud
الاعتماد وسياق RAA
الاعتماد وسياق RAA
Registrar accreditation and DNS abuse obligations
For the registrable domain consensys-digital.cloud behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
تحليل VirusTotal
هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب