MALICIOUS — CRITICAL
my1.finance – Active Crypto Drainer Site, High Risk
my1[.]
Analysis indicates that the domain my1.finance was registered on 14 June 2026 through GNAME.COM PTE.
- VirusTotal
- 19/91
- Blocklists
- 2 · MetaMask, SEAL
- Availability
- Last known active · HTTP 200
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Notification and current-status evidence
The sent-report ledger records the first outgoing report at .
The recorded recipient is complaint@gname.com.
The latest stored availability evidence still shows the domain reachable; 1 month has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
Jump to section
Evidence Analysis
Analysis indicates that the domain my1.finance was registered on 14 June 2026 through GNAME.COM PTE. LTD. and resolves to 188.114.97.3, an address owned by Cloudflare (AS13335) located in the United States. The web server returns HTTP 200 and presents a page titled “TRADE”. Automated fingerprinting reveals a stack consisting of PHP, ThinkPHP, Bootstrap, Vue.js, LiveChat, jQuery and Cloudflare services, with the SSL certificate issued by Google Trust Services / WE1. Gridinsoft assigned a trust score of 0/100, and VirusTotal reports 14 of 91 scanners flagging the domain. The site is classified as a crypto drainer, is currently active, and has been blocked by PhishDestroy, MetaMask and SEAL as well as listed on three public blocklists. Nameservers are coen.ns.cloudflare.com and kimora.ns.cloudflare.com. While the classification and infrastructure are confirmed, the specific payload or transaction flow has not been publicly disclosed. Defenders should proactively block the domain and its resolving IP, incorporate the observed technology signatures into detection rules, and monitor DNS and network logs for related activity. Continued surveillance is recommended to track any changes to the infrastructure or threat behavior.
Stored source results
Recorded verdicts and infrastructure observations for this domain.
Data coverage12 recorded checks
Network Security Intelligence
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Hagezi Threat Feed | cdn.staticfile.org |
malicious | Sinkholed |
| DNS4EU | my1.finance |
malicious | Sinkholed |
Threat Response Pipeline
Public Blocklist Status
Stored Capture
Domain Intelligence
Technical detailsDNS, SSL SANs, timestamps
ICANN OVERSIGHT
Accreditation and RAA context
Accreditation and RAA context
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Technologies · 9 identified
ThinkPHP is an open-source PHP framework with MVC structure developed and maintained by Shanghai Topthink Company.
www.thinkphp.cn 100% confidenceBootstrap is a free and open-source CSS framework directed at responsive, mobile-first front-end web development. It contains CSS and JavaScript-based design templates for typography, forms, buttons, navigation, and other interface components.
getbootstrap.com 100% confidenceVue.js is an open-source model–view–viewmodel JavaScript framework for building user interfaces and single-page applications.
vuejs.org 100% confidenceLiveChat is an online customer service software with online chat, help desk software, and web analytics capabilities.
www.livechat.com 100% confidencejQuery is a JavaScript library which is a free, open-source software designed to simplify HTML DOM tree traversal and manipulation, as well as event handling, CSS animation, and Ajax.
jquery.com 100% confidenceCloudflare Browser Insights is a tool that measures the performance of websites from the perspective of users.
www.cloudflare.com 100% confidenceCloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com 100% confidenceHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100% confidenceVirusTotal Analysis
Evidence & External ReportsIndependent lookups and source reports
PD-20260618-7E4EE9 Recipient: complaint@gname.com Victim safety and official reportingImmediate actions and verified reporting channels
If a wallet, seed phrase, or account was exposed, report the incident immediately. Revoke approvals and move remaining assets to a new wallet created on a trusted device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Wallet incident responseActions, evidence preservation, and official reporting
Use this section only if you connected a wallet, signed a transaction, disclosed a seed phrase, or transferred funds through my1.finance.
What should I do immediately?
Urgent
- Revoke token approvals — use revoke.cash to remove access granted to malicious smart contracts
- Move remaining funds to a brand-new wallet. The compromised wallet is no longer safe
- Change all passwords — email, exchange accounts, anything that shares the same password
- Enable 2FA using an authenticator app (not SMS). Disable SMS-based recovery
- Freeze cards if you entered banking details on the phishing site
What information should I collect for my report?
FBI guidelines
According to the FBI, the most important details are transaction data:
- Cryptocurrency addresses — scammer's wallet (e.g.,
0x5856...35985) - Amount & crypto type — exact amount (e.g., 1.02345 ETH, 0.5 BTC, 500 USDT)
- Transaction ID (hash) — the unique blockchain transaction identifier
- Exact dates & times — of each transaction and first contact with scammer
- Screenshots — scam website, chat messages, emails, wallet transactions, social media
- All URLs & domains used by the scammer (including
my1.finance) - Communications — emails, texts, phone numbers, usernames the scammer used
Even if you don't have all details — file a report anyway. Partial information still helps investigations.
Where should I report the scam?
- FBI IC3 — Internet Crime Complaint Center (US federal reporting)
- Europol — European cybercrime reporting (EU)
- Chainabuse — flag scam wallets across exchanges & platforms
- Your crypto exchange — notify its fraud team immediately; it may be able to preserve records or restrict funds held on its platform
- Local police — creates an official record, even if they can't act immediately
A report is not a guarantee of recovery or investigation, but prompt, accurate transaction data can help authorities and service providers trace the incident.
How do crypto scams typically work?
- Fake websites — pixel-perfect clones of legitimate sites with slightly altered domains
- Malicious approvals — "connect wallet" prompts that grant unlimited token spending to attackers
- Pig butchering — trust built over weeks via Telegram/WhatsApp/dating apps, then money stolen
- Recovery scams — fraudsters pose as recovery agents and demand upfront fees. Never share a seed phrase or pay before independently verifying the provider
- Fake ads & airdrops — Google/social media ads and "free token" offers leading to wallet drainers
- AI-powered scams — deepfakes, automated phishing, and AI-generated sites making fraud harder to detect
How can I protect myself in the future?
- Use a hardware wallet (Ledger, Trezor). Never store large amounts in browser wallets
- Bookmark official sites — never click links from emails, DMs, or ads
- Read every approval — verify permissions before signing. Reject unlimited approvals
- Verify domains — check on PhishDestroy before interacting. Check HTTPS, spelling, domain age
- "Too good to be true" = scam — guaranteed returns, celebrity endorsements, urgent deadlines