VirusTotal
7 / 95
“MindAI: Staking | Address: 0xf1597a0a...5486fb089 | Etherscan”
The domain etherscan-unstake-0xf1597a0a0d4ad58.onradar.network, impersonating the brand Arbitrum, has a critical threat score of 100/100 and is currently down. It has been flagged as malicious by 7 out of 95 security vendors, including notable names like Kaspersky and BitDefender, and is listed on 2 public blocklists. Google Safe Browsing has not flagged this domain, indicating it may have been operational for a limited time before being taken down.
Registered with Cloudflare, Inc., the domain's hosting IP is 188.114.97.3. The domain was first seen on 2025-10-07, suggesting it was recently created for malicious purposes. The presence of the Angel Drainer indicates a specific targeting of cryptocurrency assets.
Block the domain at the perimeter and submit a report to the registrar abuse desk to mitigate any potential impact.
Full extracted values, their blockchain and collection source. An address found in page content does not establish who controls it.
0x1CbFF69E67C93C24AE8E2B5331EF51F69b945E88Format validated · Domain analysis0x1a8c56C15392497C20F35296bE5aa7146577444cFormat validated · Domain analysis0x2E5576B475E4710a0Ec59674842996a40781dDA0Format validated · Domain analysis0x3F1e24e220b833dE23C11f541a1F421cCbb6570DFormat validated · Domain analysis0x5d94f71196F88DCF8481E2153021bCa3F2948FA3Format validated · Domain analysis0x5e65dee5Aa03B50A7Ea086B135eAe3B0AC4360d4Format validated · Domain analysis0x693a6cd57237D090108074565398e5D30fDB6874Format validated · Domain analysis0x702d1AD579D45B2591E501949994f1f202854ac6Format validated · Domain analysis0x71c7656ec7ab88b098defb751b7401b5f6d8976fFormat validated · Domain analysis0x811CB045a44B629707402cd56358D90a472915b8Format validated · Domain analysis0x92F4C76e59969Da1272f7f26cEeFCe47470Ca73fFormat validated · Domain analysisIoC extraction recorded 2026-08-02 04:35:23 UTC
Stored crawler-versus-browser observations for this host, plus a live fingerprint check for Keitaro-style traffic distribution systems.
Scanner note: unavailable: raw=connection_error; http=0; via=http_proxy; error=SOCKSHTTPConnectionPool(host='etherscan-unstake-0xf1597a0a0d4ad58.onradar.network', port=80): Max retries exceeded with
For the registrable domain onradar.network behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Edge-IP reputation is not attributed to this domain.
Location describes the IP network.
13 recorded events. These records describe collected evidence, outgoing notifications and publication; they do not confirm a complete investigation or a takedown.
We scan suspicious URLs, inspect public results and send evidence through the appropriate abuse-reporting channels. The dated events above show what is recorded for this domain. The directory below explains the wider workflow.
Capture the rendered page, requests and visible infrastructure.
Compare the available engine results and retain the analysis timestamp.
Check whether Google currently lists the URL as unsafe.
Inspect a public scan and its recorded network and classification data.
Look for indicator references and related community intelligence.
Compare archived captures and preserve historical context.
Look for matching indicators and associated threat records.
Inspect certificate records and related hostnames.
Compare security resolver responses and record observed blocking.
Inspect the public DNS, TLS, HTTP and technology surface.
Security services used for scanning, reputation checks and reporting are listed below. A service being listed is not evidence that it received, accepted or acted on this particular domain. Recorded submissions appear in the notification history above.
28 stored lookalike domains
Reported by 1 community member, first seen Oct 7, 2025
If a wallet, seed phrase, or account was exposed, report the incident immediately. Revoke approvals and move remaining assets to a new wallet created on a trusted device.
Select your country to get official cybercrime contacts, or create a complaint draft →.
Template-based draft · optional AI wording assistance requires separate consent
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowSubmit suspicious domains to our threat database — protect the community
ReportRecent phishing reports and observed availability changes
MonitorMonitor live threats or contest this listing if you believe it's a false positive
An estimated $51 billion flowed to illicit crypto wallets in 2024 (source). If you interacted with etherscan-unstake-0xf1597a0a0d4ad58.onradar.network — act now.
According to the FBI, the most important details are transaction data:
0x5856...35985)etherscan-unstake-0xf1597a0a0d4ad58.onradar.network)Even if you don't have all details — file a report anyway. Partial information still helps investigations.
A report is not a guarantee of recovery or investigation, but prompt, accurate transaction data can help authorities and service providers trace the incident.