VirusTotal
7 / 93
“StealthHash - Cryptocurrency Crime Fighters”
Analysis of stealth-hash.support indicates that the domain was registered on 12 October 2025 through Hostinger operations, UAB and is currently taken offline. The site resolved to the IPv6 address 2a02:4780:4c:1604:fb4f:1e7d:cbc9:77b1, which is assigned to AS47583 Hostinger International Limited and geolocated to the United States. No TLS certificate was observed, meaning the site operated without HTTPS. The page title returned by the server was “StealthHash - Cryptocurrency Crime Fighters,” and the domain explicitly impersonates the Ethereum brand, aligning with the reported wallet/seed phishing campaign. Reputation data show that the domain appears on a single security blocklist and is referenced in one AlienVault OTX pulse.
VirusTotal scans recorded seven detections out of ninety‑three security vendors, confirming that multiple scanners flagged the domain as malicious. Independent anti‑phishing services such as PhishDestroy have also blocked the domain, and Gridinsoft assigned a trust score of 0 out of 100, indicating a complete lack of credibility. The authoritative nameservers are ns1.dns-parking.com and ns2.dns-parking.com, both typical of parked or low‑cost hosting services. While the offline status limits immediate observation of the payload or credential‑harvesting mechanisms, the combination of brand impersonation, wallet/seed phishing classification, and the observed detections strongly suggests a malicious intent to harvest cryptocurrency private keys or seed phrases from unsuspecting Ethereum users.
The lack of SSL further reduces the trustworthiness of the site and may facilitate man‑in‑the‑middle interception of submitted data. Defenders should continue to block the IPv6 address and the domain at network perimeter devices, update URL filtering and threat‑intel feeds with the domain and its associated IP, and monitor for any resurgence of the domain or similar patterns hosted on Hostinger infrastructure.
Full extracted values, their blockchain and collection source. An address found in page content does not establish who controls it.
12SVakQb87h2Xk6qLTSt3denzaGqMD9QinFormat validated · Domain analysis1PRugWeVRR7aAuSJJVit2mp2gb4HqCCbMnFormat validated · Domain analysis33yPjjSMGHPp8zj1ZXySNJzSUfVSbpXEuLFormat validated · Domain analysis3Dv7gDyzAAd3CY3i1TayRb7BctWp2BJpFUFormat validated · Domain analysis3Gzx1DBE6crXivedrHdmtxt57goP6WgkdoFormat validated · Domain analysisbc1q2unnczt9w6a6mh273lt8w3w8tgvcmz3wnwymklFormat validated · Domain analysisbc1qcygs9dl4pqw6atc4yqudrzd76p3r9cp6xp2knyFormat validated · Domain analysisbc1ql6amrvwvmge6gq37n5nnw0gq8y4fafddsygjc0Format validated · Domain analysis0x53d0e4dab3e125dd25ecfb24ca610075fa9bc8e1Format validated · Domain analysis0xcf59adef2954ceeb1b9a4c6a6198760df0b45c9fFormat validated · Domain analysisTK72J7YwNqkeqEsbbhcSZTG6QXWTQgX7dAFormat validated · Domain analysisTLMmc51oYQBUcBPcLuUeqhREaP118HUZqZFormat validated · Domain analysisIoC extraction recorded 2026-08-02 04:18:36 UTC
Stored crawler-versus-browser observations for this host, plus a live fingerprint check for Keitaro-style traffic distribution systems.
Scanner note: unavailable: raw=connection_error; http=0; via=http_proxy; error=SOCKSHTTPConnectionPool(host='stealth-hash.support', port=80): Max retries exceeded with url: / (Caused by NewConnection
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
ns2.dns-parking.comns1.dns-parking.comLocation describes the IP network.
12 recorded events. These records describe collected evidence, outgoing notifications and publication; they do not confirm a complete investigation or a takedown.
We scan suspicious URLs, inspect public results and send evidence through the appropriate abuse-reporting channels. The dated events above show what is recorded for this domain. The directory below explains the wider workflow.
Capture the rendered page, requests and visible infrastructure.
Compare the available engine results and retain the analysis timestamp.
Check whether Google currently lists the URL as unsafe.
Inspect a public scan and its recorded network and classification data.
Look for indicator references and related community intelligence.
Compare archived captures and preserve historical context.
Look for matching indicators and associated threat records.
Inspect certificate records and related hostnames.
Compare security resolver responses and record observed blocking.
Inspect the public DNS, TLS, HTTP and technology surface.
Security services used for scanning, reputation checks and reporting are listed below. A service being listed is not evidence that it received, accepted or acted on this particular domain. Recorded submissions appear in the notification history above.
52 stored lookalike domains
Reported by 1 community member, first seen Dec 29, 2025
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Select your country to get official cybercrime contacts, or create a complaint draft →.
Template-based draft · optional AI wording assistance requires separate consent
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowSubmit suspicious domains to our threat database — protect the community
ReportRecent phishing reports and observed availability changes
MonitorMonitor live threats or contest this listing if you believe it's a false positive