sso-ndax-lginapp-cdn[.]webflow[.]io
“NDAX® | Login: Canada’s Most Secure Crypto Exchange”
sso-ndax-lginapp-cdn.webflow.io — المحتوى غير متوفر. نوع الاحتيال: Fake Exchange. ملخص الأدلة: VirusTotal 16/91 (alphaMountain.ai, BitDefender, Chong Lua Dao, CyRadar, ESET); CF Radar malicious; PhishDestroy score 95/100. مسجّل النطاق: Webflow.
يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.
This domain is actively engaged in crypto credential theft, specifically targeting users of the legitimate NDAX cryptocurrency exchange platform. Analysis indicates the infrastructure is designed to harvest login credentials, potentially enabling unauthorized access to user accounts and subsequent theft of digital assets. The page title, 'NDAX® | Login: Canada’s Most Secure Crypto Exchange,' directly mirrors the branding of the authentic exchange, increasing the likelihood of successful deception among users seeking to access their accounts. Infrastructure analysis reveals multiple high-confidence threat indicators. The domain, registered through Webflow, resolves to the IP address 104.18.36.248 and is currently flagged by 15 out of 95 security vendors on VirusTotal. Additionally, the domain appears on one security blocklist, further corroborating its malicious intent. While the exact creation date of the domain is not publicly disclosed, the combination of brand impersonation, active status, and vendor detections strongly suggests a recently deployed phishing operation. Users who have visited this domain or entered credentials should take immediate action to mitigate potential risks. First, revoke any active sessions on the legitimate NDAX platform and reset account passwords using a secure, unrelated device. Enable multi-factor authentication if not already active, and monitor all linked accounts for unauthorized transactions or suspicious activity. If financial loss is suspected, report the incident to relevant authorities and the legitimate exchange to initiate fraud response protocols. Given the high-risk nature of this threat, affected users should also consider scanning their devices for malware or unauthorized access tools.
استخبارات أمن الشبكات
مسار الاستجابة للتهديدات Pipeline
حالة قوائم الحظر العامة
التقنيات · 3 identified
Cloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com ثقة 100٪HTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org ثقة 100٪تحليل VirusTotal
الأدلة والتقارير الخارجية
هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب