Search our database of flagged domains. Check if a website is a scam, phishing, or legitimate.

0
Total Tracked
0
Detected
0
Content Alive
0
Content Dead
0
VT Pending
Ice Phishing
HIGH THREAT

Understanding and Combating Ice Phishing Threats

Ice Phishing is a growing threat with 42 domains detected, 8 of which are currently active. The top TLDs are .com and .app, with arin as a leading registrar.

42
Domains Detected
HIGH
Threat Level

How This Attack Works

Ice Phishing is a sophisticated technique that targets users by manipulating blockchain transactions. Here's how it typically unfolds.

STEP 1
Target Identification
Attackers identify potential victims, often targeting users with significant cryptocurrency holdings.
STEP 2
Setup Spoofed Environment
The attacker creates a fake website or app mimicking a legitimate service to deceive users.
STEP 3
Credential Harvesting
Users are tricked into entering sensitive information, allowing attackers to gain access to their accounts.
STEP 4
Unauthorized Transactions
With access to the victim's account, attackers execute unauthorized transactions, siphoning funds.

Technical Analysis

Ice Phishing attacks often involve the use of malicious smart contracts that exploit users by redirecting transactions to the attacker's wallet. Attackers employ social engineering techniques to lure victims into signing transactions that they believe are legitimate. These transactions often use clever code obfuscation to hide the true nature of the transaction. Attackers also leverage compromised infrastructure, such as DNS servers or hosting services like those registered through arin or Vercel Inc., to create convincing phishing environments. By mimicking legitimate services, these attacks bypass traditional security checks, making detection challenging.

Real Cases

Ethereum Wallet Scam (2023)
$1.2 million stolen
Attackers used a fake wallet service to steal credentials, resulting in a substantial loss of Ethereum funds.
Crypto Exchange Phishing (2024)
$2.5 million stolen
A phishing site mimicking a popular exchange tricked users into entering their login details, leading to significant asset theft.
DeFi Platform Breach (2024)
$3.8 million stolen
A decentralized finance platform was targeted by ice phishers who exploited smart contract vulnerabilities to siphon funds.

How to Detect

Unusual domain names that closely resemble legitimate services
Unexpected requests for private keys or seed phrases
Emails or messages urging immediate action on your crypto assets
Anomalies in transaction requests, such as unexpected gas fees
Lack of HTTPS encryption on websites requiring sensitive input

How to Protect Yourself

1 Always verify the URL before entering sensitive information
2 Enable two-factor authentication on all accounts
3 Regularly monitor transaction logs for unauthorized activities
4 Educate yourself about common phishing tactics
5 Use hardware wallets for enhanced security

Frequently Asked Questions

What is Ice Phishing?
Ice Phishing is a cyber threat where attackers deceive users into authorizing fraudulent transactions by mimicking legitimate services.
How much money has been stolen through Ice Phishing?
Ice Phishing has resulted in millions of dollars of losses, with notable cases like the Ethereum Wallet Scam in 2023 costing $1.2 million.
How do I protect myself from Ice Phishing?
Stay vigilant, verify URLs, use two-factor authentication, and maintain awareness of phishing tactics to protect yourself.
What should I do if I'm a victim of Ice Phishing?
Immediately report to your financial institution, change credentials, and alert local authorities and platforms like PhishDestroy.
Data sourced from PhishDestroy threat intelligence database — 42 domains tracked for this threat type
Ice Phishing — Threat Intelligence Token Approval Low Activity
42
Domains
4
Alive
37
Taken Down
8.2
Avg VT
9.5%
Alive Rate
81%
Detected
Since Mar 2024 23 domains with VT ≥ 5
Ice Phishing 42 domains
Screenshot of rectification-fixuserauthentication.vercel.app
rectification-fixuserauthentication.vercel.app
23 VTUnknown
Screenshot of rectification-fixuserauthentication.vercel.app
rectification-fixuserauthentication.vercel.app
Screenshot of authwalletconnect.com
authwalletconnect.com
20 VTUnknownBinance
Screenshot of authwalletconnect.com
authwalletconnect.com
Screenshot of rectifyissues-now.vercel.app
rectifyissues-now.vercel.app
20 VTUnknown
Screenshot of rectifyissues-now.vercel.app
rectifyissues-now.vercel.app
Screenshot of supports-rectification.vercel.app
supports-rectification.vercel.app
17 VTUnknown
Screenshot of supports-rectification.vercel.app
supports-rectification.vercel.app
Screenshot of seaportal.fo
seaportal.fo
15 VTUnknown
Screenshot of seaportal.fo
seaportal.fo
Screenshot of flaretokensdrop.com
flaretokensdrop.com
13 VTUnknowngoogle
Screenshot of flaretokensdrop.com
flaretokensdrop.com
Screenshot of agencyanalyticsframe.us.com
agencyanalyticsframe.us.com
12 VTCF Banned
Screenshot of agencyanalyticsframe.us.com
agencyanalyticsframe.us.com
Screenshot of flrconnectportal.live
flrconnectportal.live
12 VTUnknownstargate
Screenshot of flrconnectportal.live
flrconnectportal.live
Screenshot of enacoin-newbridge.com
enacoin-newbridge.com
11 VTLive
Screenshot of enacoin-newbridge.com
enacoin-newbridge.com
Screenshot of airdrop.wrlomhole.net
airdrop.wrlomhole.net
10 VTUnknownacross
Screenshot of airdrop.wrlomhole.net
airdrop.wrlomhole.net
Screenshot of aoerodrome.finance
aoerodrome.finance
10 VTUnknown
Screenshot of aoerodrome.finance
aoerodrome.finance
Screenshot of chainxtrade.com
chainxtrade.com
10 VTUnknownchainlink
Screenshot of chainxtrade.com
chainxtrade.com
Screenshot of ethdrawclaimdrop.org
ethdrawclaimdrop.org
10 VTLiveacross
Screenshot of ethdrawclaimdrop.org
ethdrawclaimdrop.org
Screenshot of test123.sphere-drainer.cc
test123.sphere-drainer.cc
10 VTUnknowncsgo
Screenshot of test123.sphere-drainer.cc
test123.sphere-drainer.cc
Screenshot of arb.claimscrypto.top
arb.claimscrypto.top
9 VTUnknownAirdrop Scam
Screenshot of arb.claimscrypto.top
arb.claimscrypto.top
Screenshot of eth-drainer.exontra.com
eth-drainer.exontra.com
8 VTUnknown
Screenshot of eth-drainer.exontra.com
eth-drainer.exontra.com
Screenshot of drnr.fiznen.com
drnr.fiznen.com
7 VTUnknownbinance
Screenshot of drnr.fiznen.com
drnr.fiznen.com
Screenshot of h2-finance.web.app
h2-finance.web.app
7 VTUnknown
Screenshot of h2-finance.web.app
h2-finance.web.app
Screenshot of xrpdistributions.firebaseapp.com
xrpdistributions.firebaseapp.com
7 VTUnknownAirdrop Scam
Screenshot of xrpdistributions.firebaseapp.com
xrpdistributions.firebaseapp.com
Screenshot of ngcrp.com
ngcrp.com
6 VTUnknownbinance
Screenshot of ngcrp.com
ngcrp.com
Screenshot of drainer.bexcapitaltrade.com
drainer.bexcapitaltrade.com
5 VTUnknownbinance
Screenshot of drainer.bexcapitaltrade.com
drainer.bexcapitaltrade.com
Screenshot of flare.linkportalnet.com
flare.linkportalnet.com
5 VTLivestargate
Screenshot of flare.linkportalnet.com
flare.linkportalnet.com
Screenshot of trovako.com
trovako.com
5 VTUnknownbinance
Screenshot of trovako.com
trovako.com
Screenshot of arbitriums.icu
arbitriums.icu
4 VTUnknownarbitrum
Screenshot of arbitriums.icu
arbitriums.icu
virtualsget.xyz
4 VTUnknownAirdrop Scam
Screenshot of xrpdistributions.web.app
xrpdistributions.web.app
4 VTUnknownAirdrop Scam
Screenshot of xrpdistributions.web.app
xrpdistributions.web.app
Screenshot of ledgerlane.icu
ledgerlane.icu
3 VTUnknownLedger
Screenshot of ledgerlane.icu
ledgerlane.icu
Screenshot of megaethlabs.top
megaethlabs.top
3 VTUnknownAirdrop Scam
Screenshot of megaethlabs.top
megaethlabs.top
Screenshot of www.amlcheckvault.com
www.amlcheckvault.com
3 VTUnknownAML Scam
Screenshot of www.amlcheckvault.com
www.amlcheckvault.com
Screenshot of lumiachain.com
lumiachain.com
2 VTUnknownchainlink
Screenshot of lumiachain.com
lumiachain.com
Screenshot of semantic.nexus-innovators.site
semantic.nexus-innovators.site
2 VTUnknownbnb chain
Screenshot of semantic.nexus-innovators.site
semantic.nexus-innovators.site
Screenshot of bitrane.com
bitrane.com
1 VTUnknownavalanche
Screenshot of bitrane.com
bitrane.com
Screenshot of defi-launch.io
defi-launch.io
1 VTUnknownaave
Screenshot of defi-launch.io
defi-launch.io
Screenshot of metaversentf.com
metaversentf.com
1 VTUnknowndiscord
Screenshot of metaversentf.com
metaversentf.com
Screenshot of app.carvs-webs.com
app.carvs-webs.com
Unknowndiscord
Screenshot of app.carvs-webs.com
app.carvs-webs.com
Screenshot of bridge.maob.site
bridge.maob.site
Livebinance
Screenshot of bridge.maob.site
bridge.maob.site
Screenshot of claim.mindof-pepe.world
claim.mindof-pepe.world
Unknown
Screenshot of claim.mindof-pepe.world
claim.mindof-pepe.world
Screenshot of dymensionrollapps.com
dymensionrollapps.com
Unknowndiscord
Screenshot of dymensionrollapps.com
dymensionrollapps.com
Screenshot of etherfn.icu
etherfn.icu
Unknownallbridge
Screenshot of etherfn.icu
etherfn.icu
Screenshot of fincaptor.app
fincaptor.app
Unknownbinance
Screenshot of fincaptor.app
fincaptor.app
Screenshot of publicsale.well3.website
publicsale.well3.website
Unknowndiscord
Screenshot of publicsale.well3.website
publicsale.well3.website
Screenshot of randombitcoins.com
randombitcoins.com
Unknownaave
Screenshot of randombitcoins.com
randombitcoins.com