pengu.exchange
“しばらくお待ちください...”
pengu.exchange flagged as crypto drainer phishing. 0/95 VirusTotal detections, registered via NiceNIC, Cloudflare-hosted, blocked by 3 security lists.
The detailed PhishDestroy AI analysis below remains in English to preserve the original forensic record.
Evidence Summary
This domain is flagged as a crypto drainer phishing site targeting users with fraudulent wallet-draining mechanisms. Analysis indicates the infrastructure is designed to mimic legitimate exchange or wallet services, likely exploiting users through deceptive prompts to connect wallets or input recovery phrases. The Japanese page title "しばらくお待ちください..." ("Please wait a moment...") suggests a localized or obfuscated attack vector, potentially serving as a placeholder or redirect to malicious payloads. Infrastructure analysis reveals the domain was registered on December 30, 2025, through NiceNIC International Group Co., Limited, a registrar frequently associated with high-risk registrations. It resolves to IP address 172.67.161.233, a Cloudflare-protected endpoint leveraging HTTP/3 and HSTS for apparent legitimacy. Despite 0 detections across 95 VirusTotal engines, the domain appears on 3 security blocklists and is referenced in 1 AlienVault OTX threat intelligence pulse. The SSL certificate is issued by Google Trust Services, a common tactic to evade initial scrutiny. MetaMask, SEAL, and PhishDestroy have preemptively blocked access, indicating prior detection of malicious behavior. Mitigation steps for this crypto drainer threat include immediate blacklisting of the domain and IP in network security controls. Organizations should monitor for connections to 172.67.161.233 and alert on any attempts to access pengu.exchange. Users should be educated to verify domain authenticity before connecting wallets or entering credentials, particularly for services impersonating exchanges. Given the domain's recent creation and Cloudflare obfuscation, security teams should prioritize retroactive log analysis for any prior interactions with this infrastructure. Blocking domains registered via NiceNIC with similar patterns (e.g., future-dated creation, Cloudflare hosting) may preemptively disrupt related campaigns.
Network Security Intelligence Registrar context
Forensic History & Detection Timeline
-
VirusTotal Detections Update Jun 27, 2026 · 02:41 UTCVirusTotal scanner detections updated from 7 to 0. Resolved alerts: CRDF, CyRadar, Fortinet, Gridinsoft, SOCRadar, Seclookup, alphaMountain.ai.
-
Cloudflare Radar Scan Mar 7, 2026 · 10:52 UTCCloudflare Radar scan registered: View Radar report.
-
Domain Status Transition Feb 28, 2026 · 07:01 UTCDomain state transitioned from alive to dead.
Threat Response Pipeline
Public Blocklist Status
Stored Capture · 2 sources
Domain Intelligence
Technical detailsDNS, SSL SANs, timestamps
ICANN OVERSIGHT
Accreditation and RAA context
Accreditation and RAA context
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Latest Classified Outcome 2026-09-16 02:43:49 UTC
Technologies · 3 identified
VirusTotal Analysis
Archived Evidence
Site Performance Analysis
Google PageSpeed Insights — mobile performance audit of pengu.exchange · checked Jun 27, 2026
Stored outcome evidence
Outcome & takedown attribution
- Outcome
Community reports
Reported by 1 community member, first seen Jan 4, 2026
- Stored reports
- 1
- Unique reported URLs
- 1
Evidence & External Reports
Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive