toucan-delegator[.]cabana[.]fi
“Delegate - PoolTogether”
toucan-delegator.cabana.fi — المحتوى غير متوفر (HTTP 502). انتحال العلامة التجارية: ["optimism"]; نوع الاحتيال: Crypto Drainer. ملخص الأدلة: VirusTotal 6/94 (alphaMountain.ai, CRDF, CyRadar, ESET, Gridinsoft); PhishDestroy score 68/100. مسجّل النطاق: Gandi SAS.
يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.
This domain, toucan-delegator.cabana.fi, presents a targeted credential theft threat specifically designed to impersonate PoolTogether’s delegation interface. Analysis indicates the site was engineered to harvest cryptocurrency wallet credentials and private keys under the guise of a legitimate delegation portal. The fraudulent page mimics PoolTogether’s branding, including an identical page title, 'Delegate - PoolTogether,' to deceive users into entering sensitive authentication details, which would then be exfiltrated to attacker-controlled infrastructure. Infrastructure analysis reveals the domain was registered through Gandi SAS on March 27, 2026, an anomalous future date suggesting potential domain spoofing or registry manipulation. The domain resolved to the IP address 76.76.21.123 and was flagged by 6 out of 95 security vendors on VirusTotal, indicating moderate detection coverage. Additionally, the domain appeared on one security blocklist prior to being taken offline, further corroborating its malicious intent. The Gridinsoft trust score of 0/100 underscores the domain’s complete lack of legitimacy. Users who visited toucan-delegator.cabana.fi should immediately revoke any active sessions or delegations associated with the fraudulent site. All credentials, private keys, or recovery phrases entered on the page must be considered compromised and should be rotated across all platforms where they were reused. Monitor connected wallets for unauthorized transactions and review recent delegation activities for anomalies. If financial loss occurred, report the incident to relevant blockchain analytics platforms and local cybercrime authorities with the domain, IP address 76.76.21.123, and seed identifier c0e610 for further investigation.
استخبارات أمن الشبكات
مسار الاستجابة للتهديدات Pipeline
حالة قوائم الحظر العامة
تحليل VirusTotal
تحليل أداء الموقع
Google PageSpeed Insights — mobile performance audit of toucan-delegator.cabana.fi · checked Jun 26, 2026
الأدلة والتقارير الخارجية
PD-20260328-270DB6 Recipient: abuse@vercel.com هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب