snoonauts[.]xyz
“Nur einen Moment…”
snoonauts.xyz — Inhalt nicht verfügbar (HTTP 502). Zusammenfassung der Beweislage: VirusTotal 3/95 (alphaMountain.ai, Forcepoint ThreatSeeker, Fortinet); PhishDestroy score 65/100. Registrar: PDR.
Die ausführliche Analyse von PhishDestroy AI bleibt auf Englisch, damit der ursprüngliche forensische Bericht unverändert bleibt.
This domain, snoonauts.xyz, is identified as a cryptocurrency phishing infrastructure targeting German-speaking users. Analysis of the page title 'Nur einen Moment…' suggests an imitation of a temporary authentication or loading screen, commonly used to deceive victims into entering wallet credentials or private keys. No direct association with a specific brand or drainer kit has been confirmed, though the generic phishing classification and German-language indicators align with known wallet-draining campaigns in the region. The domain exhibits characteristics typical of credential-harvesting operations, including the absence of a legitimate SSL certificate and the use of a transient page title to mask malicious intent. Infrastructure analysis reveals the following technical indicators: the domain was registered on July 19, 2025, through PDR Ltd. d/b/a PublicDomainRegistry.com. It resolves to the IP address 104.21.32.1, a Cloudflare proxy endpoint often leveraged to obscure hosting origins. VirusTotal detections report 3 out of 95 security vendors flagging the domain as malicious, while it appears on a single security blocklist. No entries were found in Google Safe Browsing at the time of assessment, though this does not preclude prior or intermittent listings. The lack of an SSL certificate further reduces the domain’s legitimacy, as modern phishing campaigns typically employ encryption to appear credible. The domain is currently offline, likely due to takedown efforts or operational rotation by the threat actor. While the immediate risk of interaction is mitigated, the infrastructure remains a potential threat due to its recent registration and known association with phishing activity. Users who may have visited the domain are advised to monitor for unauthorized transactions, revoke any connected wallet sessions, and verify device integrity for malware. Organizations should update blocklists to include snoonauts.xyz and its resolving IP to prevent future access. Given the elevated risk classification, continued vigilance is warranted, particularly for individuals or entities targeted by German-language phishing campaigns.
Pipeline zur Reaktion auf Sicherheitsbedrohungen
Status der öffentlichen Sperrliste
Gespeicherte Aufnahme
Domain-Intelligenz
Technische DetailsDNS, SSL-SANs, Zeitstempel
ICANN OVERSIGHT
Akkreditierung und RAA-Kontext
Akkreditierung und RAA-Kontext
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Forensische Erkenntnisse
VirusTotal-Analyse
Nachweise und externe Berichte
Wurden Sie von dieser Website betroffen?
Wenn Sie Kontoanmeldeinformationen, persönliche oder Zahlungsinformationen eingegeben oder eine Datei von dieser Domain heruntergeladen haben, ergreifen Sie sofort Maßnahmen. Nachfolgend finden Sie Ressourcen, die Ihnen helfen, den Vorfall zu melden und sich zu schützen.
Melden Sie sich bei Ihren örtlichen Behörden
Wählen Sie Ihr Land aus, um Offizielle Kontakte im Bereich Cyberkriminalität oder einen Beschwerdeentwurf erstellen → zu erhalten.
Jede beliebige Domain prüfen
Bedrohungsanalyse anhand gespeicherter Blocklisten, WHOIS, DNS und öffentlicher Scan-Beweise
Jetzt scannenPhishing melden
Melden Sie verdächtige Domains an unsere Bedrohungsdatenbank – schützen Sie die Community
MeldenEchtzeit-Bedrohungsfeed
Aktuelle Phishing-Meldungen und beobachtete Verfügbarkeitsänderungen
ÜberwachenBleiben Sie auf dem Laufenden, bleiben Sie sicher
Beobachten Sie aktuelle Bedrohungen oder legen Sie Widerspruch gegen diesen Eintrag ein, wenn Sie der Meinung sind, dass es sich um einen Fehlalarm handelt