snoonauts[.]xyz
“Nur einen Moment…”
snoonauts.xyz — المحتوى غير متوفر (HTTP 502). ملخص الأدلة: VirusTotal 3/95 (alphaMountain.ai, Forcepoint ThreatSeeker, Fortinet); PhishDestroy score 65/100. مسجّل النطاق: PDR.
يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.
This domain, snoonauts.xyz, is identified as a cryptocurrency phishing infrastructure targeting German-speaking users. Analysis of the page title 'Nur einen Moment…' suggests an imitation of a temporary authentication or loading screen, commonly used to deceive victims into entering wallet credentials or private keys. No direct association with a specific brand or drainer kit has been confirmed, though the generic phishing classification and German-language indicators align with known wallet-draining campaigns in the region. The domain exhibits characteristics typical of credential-harvesting operations, including the absence of a legitimate SSL certificate and the use of a transient page title to mask malicious intent. Infrastructure analysis reveals the following technical indicators: the domain was registered on July 19, 2025, through PDR Ltd. d/b/a PublicDomainRegistry.com. It resolves to the IP address 104.21.32.1, a Cloudflare proxy endpoint often leveraged to obscure hosting origins. VirusTotal detections report 3 out of 95 security vendors flagging the domain as malicious, while it appears on a single security blocklist. No entries were found in Google Safe Browsing at the time of assessment, though this does not preclude prior or intermittent listings. The lack of an SSL certificate further reduces the domain’s legitimacy, as modern phishing campaigns typically employ encryption to appear credible. The domain is currently offline, likely due to takedown efforts or operational rotation by the threat actor. While the immediate risk of interaction is mitigated, the infrastructure remains a potential threat due to its recent registration and known association with phishing activity. Users who may have visited the domain are advised to monitor for unauthorized transactions, revoke any connected wallet sessions, and verify device integrity for malware. Organizations should update blocklists to include snoonauts.xyz and its resolving IP to prevent future access. Given the elevated risk classification, continued vigilance is warranted, particularly for individuals or entities targeted by German-language phishing campaigns.
مسار الاستجابة للتهديدات Pipeline
حالة قوائم الحظر العامة
لقطة محفوظة
معلومات النطاق
التفاصيل الفنيةDNS، أسماء المجال البديلة (SAN) في بروتوكول SSL، الطوابع الزمنية
ICANN OVERSIGHT
الاعتماد وسياق RAA
الاعتماد وسياق RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
الاستخبارات الجنائية الرقمية
تحليل VirusTotal
الأدلة والتقارير الخارجية
هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب