allocations-quant[.]network
This domain, allocations-quant.network, is flagged as a crypto credential theft operation targeting users through deceptive wallet connection prompts. Analysis indicates no direct brand impersonation, but the infrastructure mimics legitimate quantitative trading or allocation platforms to trick victims into exposing private keys or seed phrases. The absence of a known drainer kit suggests a custom or low-profile credential harvesting toolset, likely designed to evade automated detection during initial deployment. Infrastructure analysis reveals the domain was registered on March 27, 2026, through NICENIC INTERNATIONAL GROUP CO., LIMITED, a registrar frequently associated with high-risk domains. It resolves to the IP address 188.114.97.3, which has been linked to other malicious infrastructure in recent threat intelligence reports. Security vendor detections on VirusTotal stand at 4 out of 95, indicating limited but growing awareness. The domain appears on one security blocklist and has been flagged in a single threat intelligence pulse on AlienVault OTX. The page title 'Just a moment...' suggests the use of Cloudflare or similar proxy services to obscure backend infrastructure and delay takedown efforts. The domain is currently offline, likely due to enforcement actions or infrastructure rotation by the threat actor. However, the elevated risk persists due to the domain's recent creation date and the registrar's history of hosting malicious activity. Users who interacted with this domain should immediately revoke any connected wallet permissions, rotate credentials, and monitor for unauthorized transactions. Organizations should update blocklists to include this domain and its associated IP, while security teams should investigate related infrastructure for signs of compromise or lateral movement. The low detection rate on VirusTotal underscores the need for layered defenses, including real-time DNS monitoring and endpoint protection capable of identifying credential theft behaviors.
Network Security Intelligence Registrar context
Threat Response Pipeline
Public Blocklist Status
Stored Capture
Domain Intelligence
Technical detailsDNS, SSL SANs, timestamps
ICANN OVERSIGHT
Accreditation and RAA context
Accreditation and RAA context
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Latest Classified Outcome 2026-08-23 02:53:45 UTC
VirusTotal Analysis
Evidence & External Reports
PD-20260327-7E589D Recipient: abuse@nicenic.net, compliance@icann.org Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive