com-authorization-v3.digital
“com-authorization-v3.digital | 521: Web server is down”
com-authorization-v3.digital is a crypto wallet credential phishing site. Flagged by 9/95 security vendors, it mimics authorization pages to steal private keys.
The detailed PhishDestroy AI analysis below remains in English to preserve the original forensic record.
Evidence Summary
This domain, com-authorization-v3.digital, is designed to deceive users into disclosing sensitive cryptocurrency wallet credentials. The site presents itself as a legitimate authorization portal, often targeting users of decentralized finance platforms. Once credentials such as private keys or recovery phrases are entered, attackers gain full control over the victim’s digital assets, enabling unauthorized transactions and irreversible theft. Analysis indicates this domain was registered on June 04, 2026, through NICENIC INTERNATIONAL GROUP CO., LIMITED. It is currently flagged by 9 out of 95 security vendors on VirusTotal, and appears on four distinct security blocklists. The domain resolved to the IP address 104.21.72.208 and used an SSL certificate issued by Google Trust Services, a common tactic to appear legitimate. Multiple threat intelligence platforms, including two pulses on AlienVault OTX, have documented its malicious activity. If you visited com-authorization-v3.digital or entered any credentials, immediately revoke access to all connected applications and transfer assets to a new, secure wallet. Monitor all linked accounts for unauthorized transactions and enable multi-factor authentication where available. Report the incident to your wallet provider and consider filing a report with relevant cybersecurity organizations to aid in tracking the infrastructure. Do not reuse passwords or recovery phrases from compromised accounts.
Network Security Intelligence Registrar context
Forensic History & Detection Timeline
-
VirusTotal Detections Update Jun 25, 2026 · 23:53 UTCVirusTotal scanner detections updated from 8 to 9. Added scanner alerts: CyRadar, Forcepoint ThreatSeeker. Resolved alerts: G-Data.
Threat Response Pipeline
Public Blocklist Status
Evasion analysis
Cloaking suspected: scanner and victim titles differ
Stored crawler-versus-browser observations for this host, plus a live fingerprint check for Keitaro-style traffic distribution systems.
- Stored cloaking flag
- Not observed
- Cloaking score
- 0/6
- Last cloaking scan
- Server header seen by scanner
cloudflare
Scanner note: redirect: raw=redirect_301; http=301; via=http_proxy; location=https://com-authorization-v3.digital/; server=cloudflare
Stored Capture · 2 sources
Domain Intelligence
Technical detailsDNS, SSL SANs, timestamps
ICANN OVERSIGHT
Accreditation and RAA context
Accreditation and RAA context
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Latest Classified Outcome 2026-09-20 02:40:22 UTC
Technologies · 2 identified
VirusTotal Analysis
Community reports
Reported by 1 community member, first seen Jun 11, 2026
- Stored reports
- 1
- Unique reported URLs
- 1
Evidence & External Reports
Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive