appplasma[.]beauty
“Plasma - Stablecoin infrastructure for instant payments”
appplasma.beauty — Contenido no disponible. Tipo de estafa: Crypto Drainer. Resumen de las pruebas: VirusTotal 1/91 (ChainPatrol); 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 66/100. Registrador: Porkbun.
El análisis detallado de PhishDestroy AI se mantiene en inglés para conservar el registro forense original.
The domain appplasma.beauty has been flagged for hosting a generic phishing page designed to emulate Plasma, a stablecoin infrastructure project, likely targeting cryptocurrency users with an infrastructure impersonation scheme. This threat is categorized as a crypto drainer, where visitors may unknowingly connect wallets or submit payment details to malicious smart contracts or forms controlled by the attackers. The page title explicitly references 'Plasma - Stablecoin infrastructure for instant payments,' suggesting an intent to deceive users familiar with legitimate crypto infrastructure platforms. No known drainer kit signatures are publicly available at this stage, but the mimicry of a real service's branding and functional description points to a sophisticated social engineering approach aimed at convincing users of its legitimacy.
From a technical standpoint, this domain exhibits several red flags. Registered through Porkbun, LLC, it went live on September 25, 2025, and currently resolves to IP address 52.33.207.7. Despite being active, the domain remains undetected by security engines, showing 1 out of 95 detections on VirusTotal as of the latest scan. It utilizes a Let's Encrypt SSL certificate, which provides no assurance of legitimacy and is commonly abused in phishing operations for added trust signals. The domain has not been flagged by Google Safe Browsing (GSB) and remains absent from major blocklists, indicating it may be newly deployed or operating under the detection threshold. This low detection profile suggests the infrastructure is either recently operational or intentionally designed to evade early-stage monitoring.
As of this report, the domain appplasma.beauty remains active and poses an ongoing risk to unsuspecting visitors. Security researchers are actively monitoring and adding telemetry to threat intelligence feeds, but the current lack of detections means widespread public defense is not yet in place. Users are strongly advised not to interact with this domain or any linked pages, especially if prompted for wallet connections or financial transactions. PhishDestroy recommends immediate verification using its lookup tools and encourages sharing this intelligence to prevent further victimization. The risk level, currently marked as 'under_investigation,' may escalate if additional threats or campaigns are uncovered. Caution is essential given the domain’s recent creation and the high-risk nature of crypto drainer operations.
Proceso de respuesta ante amenazas Pipeline
Estado de la lista de bloqueados pública
Captura guardada
Inteligencia de dominios
Detalles técnicosDNS, SAN de SSL, marcas de tiempo
ICANN OVERSIGHT
Acreditación y contexto RAA
Acreditación y contexto RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Tecnologías · 10 identified
Webflow is Software-as-a-Service (SaaS) for website building and hosting.
webflow.com 100 % de confianzaJSDelivr is a free public CDN for open-source projects. It can serve web files directly from the npm registry and GitHub repositories without any configuration.
www.jsdelivr.com 100 % de confianzaHTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org 100 % de confianzaGoogle Tag Manager is a tag management system (TMS) that allows you to quickly and easily update measurement codes and related code fragments collectively known as tags on your website or mobile app.
www.google.com 100 % de confianzaGoogle Hosted Libraries is a stable, reliable, high-speed, globally available content distribution network for the most popular, open-source JavaScript libraries.
developers.google.com 100 % de confianzaGoogle Font API is a web service that supports open-source font files that can be used on your web designs.
google.com 100 % de confianzaGoogle Analytics is a free web analytics service that tracks and reports website traffic.
google.com 100 % de confianzaCloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com 100 % de confianzaHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100 % de confianzaAnálisis de VirusTotal
Datos y informes externos
¿Te ha afectado esta página web?
Si ingresó credenciales de cuenta, información personal o de pago, o descargó un archivo de este dominio, tome medidas inmediatas. A continuación encontrará recursos que le ayudarán a informar el incidente y protegerse.
Informa a las autoridades locales
Seleccione su país para obtener contactos oficiales de cibercrimen o crear un borrador de queja →.
Comprobar cualquier dominio
Análisis de amenazas utilizando listas de bloqueo almacenadas, WHOIS, DNS y evidencia de escaneo público
Escanear ahoraDenunciar un intento de phishing
Envía los dominios sospechosos a nuestra base de datos de amenazas: protege a la comunidad
DenunciarFlujo de amenazas en tiempo real
Informes de phishing recientes y cambios de disponibilidad observados
MonitorizarMantente informado, mantente a salvo
Supervisa las amenazas en tiempo real o impugna esta entrada si crees que se trata de un falso positivo.