rizzmas-migrate[.]lol
rizzmas-migrate.lol — المحتوى غير متوفر. نوع الاحتيال: Crypto Drainer. ملخص الأدلة: VirusTotal 4/91 (alphaMountain.ai, CRDF, Gridinsoft, SOCRadar); URLQuery 2 alerts; 1 external blocklist match (ScamSniffer); PhishDestroy score 71/100. مسجّل النطاق: Hostinger.
يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.
PhishDestroy identifies rizzmas-migrate.lol as a high-risk crypto drainer domain designed to trick users into connecting cryptocurrency wallets under the guise of a migration service. This domain mimics legitimate blockchain migration tools to deceive visitors into authorizing malicious transactions that drain funds directly from connected wallets. The threat is particularly insidious because it exploits the urgency of migration processes, where users may overlook security checks when attempting to move assets between networks or platforms. Once a user interacts with the site, the crypto drainer scans for active wallet connections and prompts fake authorization requests that, when approved, grant the attacker full access to transfer funds without further consent. Even users who disconnect their wallets after a failed transaction may still fall victim if they previously approved any permissions during their visit.
This domain was flagged by PhishDestroy with a high-risk assessment, supported by concrete technical indicators. VirusTotal analysis shows that only 1 out of 95 security vendors detected malicious activity at the time of evaluation, indicating the sophistication of the threat actor in evading detection. The domain resolves to IP address 188.114.97.3 and is registered through HOSTINGER operations, UAB, a legitimate registrar that has been misused for this campaign. Notably, rizzmas-migrate.lol was created on May 29, 2026, making it a very recent addition to the threat landscape, which often correlates with higher success rates for attackers due to the lack of historical reputation data. The domain also appears on one active security blocklist, further confirming its malicious nature. The use of Cloudflare nameservers (aryanna.ns.cloudflare.com and chad.ns.cloudflare.com) is a common tactic among threat actors to obscure their true infrastructure and evade takedown efforts.
If you visited rizzmas-migrate.lol, take immediate action to secure your cryptocurrency assets. Disconnect all wallets from the site and revoke any unauthorized permissions through your wallet provider’s official interface or tools like Etherscan’s token approval checker for Ethereum-based wallets. Scan your device for malware using reputable antivirus software, as the site may have deployed additional payloads. Report the domain to your wallet provider and consider transferring remaining funds to a new, secure wallet. Avoid interacting with similar domains promising migration services, especially those with recent creation dates or low detection rates on VirusTotal. Stay vigilant and prioritize verified, official platforms for all blockchain-related operations.
استخبارات أمن الشبكات
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DNS4EU | rizzmas-migrate.lol |
malicious | Sinkholed |
| Hagezi Threat Feed | rizzmas-migrate.lol |
malicious | Sinkholed |
مسار الاستجابة للتهديدات Pipeline
حالة قوائم الحظر العامة
لقطة محفوظة
معلومات النطاق
التفاصيل الفنيةDNS، أسماء المجال البديلة (SAN) في بروتوكول SSL، الطوابع الزمنية
ICANN OVERSIGHT
الاعتماد وسياق RAA
الاعتماد وسياق RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
تحليل VirusTotal
الأدلة والتقارير الخارجية
PD-20260624-121399 Recipient: abuse@hostinger.com هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب