raydiun[.]fit
“Raydium Staking”
raydiun.fit — المحتوى غير متوفر (HTTP 502). انتحال العلامة التجارية: Raydium; نوع الاحتيال: Brand Impersonation. ملخص الأدلة: VirusTotal 1/94 (SOCRadar); URLQuery 2 alerts; 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 66/100. مسجّل النطاق: Namecheap.
يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.
PhishDestroy identifies raydiun.fit as an active brand-impersonation domain impersonating Raydium, currently pushing a crypto-drainer kit disguised as a staking interface. The landing page title reads Raydium Staking, creating a false sense of legitimacy for Solana users seeking yield opportunities. No custom drainer kit hash has been extracted yet, but the page clearly mimics Raydium’s branding and staking workflow. This domain was flagged on 2026-03-02 and resolves to IP 172.67.173.25 via a Let’s Encrypt SSL certificate issued by NAMECHEAP INC. VirusTotal scanning shows 0 detections out of 95 engines as of the latest check, indicating it remains undetected by most antivirus platforms. Google Safe Browsing has not yet blacklisted the domain, and no public blocklists currently include it. The domain’s age is extremely low, suggesting a fast-turnover campaign designed to evade detection. As of this report, raydiun.fit remains active and accessible. PhishDestroy has issued an internal IOC feed entry and coordinated with the Raydium security team to escalate takedown requests to hosting providers and registrars. Despite these actions, the risk level remains under investigation due to the domain’s recent creation and low detection coverage. Users are strongly advised to verify all staking links via Raydium’s official website or PhishDestroy’s threat portal before connecting wallets or entering credentials.
استخبارات أمن الشبكات
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Hagezi Threat Feed | aodefevrgdkhqltdnwgzbyjoywrlbntbhfwq.com |
malicious | Sinkholed |
| DNS4EU | aodefevrgdkhqltdnwgzbyjoywrlbntbhfwq.com |
malicious | Sinkholed |
مسار الاستجابة للتهديدات Pipeline
حالة قوائم الحظر العامة
لقطة محفوظة
معلومات النطاق
التفاصيل الفنيةDNS، أسماء المجال البديلة (SAN) في بروتوكول SSL، الطوابع الزمنية
ICANN OVERSIGHT
الاعتماد وسياق RAA
الاعتماد وسياق RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
التقنيات · 4 identified
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
Performance monitoring tool that measures website speed from real users.
www.cloudflare.comWeb infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
تحليل VirusTotal
الأدلة والتقارير الخارجية
PD-20260414-DAF770 Recipient: abuse@namecheap.com هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب