auth-tec-on-db[.]shop
“Rainbow | Fun, powerful, and secure crypto wallets”
Resumen de las pruebas
The domain auth-tec-on-db.shop is a confirmed phishing site designed to operate as a wallet drainer, targeting cryptocurrency users by impersonating a legitimate crypto wallet service. It poses an elevated risk as a generic phishing threat, specifically aimed at draining funds from victims' wallets. No known brand impersonation or drainer kit was identified, but the site has been taken offline following detection.
Technical indicators confirm the malicious nature of auth-tec-on-db.shop. The domain was registered on September 22, 2025, through HOSTINGER operations, UAB, and resolves to the IP address 188.114.97.3, hosted by Cloudflare in Canada. Security vendors flagged the domain with 2 of 95 detections on VirusTotal, while it appears on 1 security blocklist (PhishDestroy). The site lacked an SSL certificate, and its page title, 'Rainbow | Fun, powerful, and secure crypto wallets,' was used to deceive users. Technologies detected include Cloudflare Browser Insights, Cloudflare, and HTTP/3. Gridinsoft assigned a trust score of 0/100, further indicating its fraudulent intent.
Victims of auth-tec-on-db.shop should immediately revoke any token approvals granted to the site and transfer remaining funds to a new, secure wallet. Users are advised to monitor their accounts for unauthorized transactions and enable additional security measures, such as hardware wallet protections. To report the phishing domain, submit it to platforms like Google Safe Browsing, PhishTank, or the registrar (HOSTINGER operations, UAB) to aid in takedown efforts and prevent further exploitation.
Instantánea de evidencia enviada
- Enviado
- Registros del libro
- 1
- ID del caso
PD-20260319-08708B- Título de la página capturada
- Rainbow | Fun, powerful, and secure crypto wallets
- Artefacto PDF
- Evidencia en PDF
Texto completo de la evidencia
Policy Violations: AUP prohibits illegal activity including fraud, phishing, malware hosting; Hostinger may suspend/terminate services and domains
Applicable Laws: Lithuanian Criminal Code (Ch. XXX, §§196–198 data/system crimes; §§214–215 electronic fraud); EU Directive 2013/40/EU
Data Coverage
Inteligencia de seguridad de red
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Nextron YARA rules | framerusercontent.com/images/aqpyngslyoccr39v0ppiulmm10a.gif?scale-down-to=512&width=640&height=640 |
malware | Detects files with GIF headers and format anomalies - which means that this image could be an obfuscated file of a different type |
Proceso de respuesta ante amenazas Pipeline
Cobertura de listas de bloqueo
10 fuentes externas supervisadas · instantánea del 13/08/2026
10 fuentes externas supervisadas Sin coincidencias
Captura guardada
Inteligencia de dominios
Detalles técnicosDNS, nombres TLS y marcas de tiempo
ICANN OVERSIGHT
Acreditación y contexto RAA
Acreditación y contexto RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Inteligencia forense
Análisis de VirusTotal
Análisis del rendimiento del sitio
Google PageSpeed Insights — mobile performance audit of auth-tec-on-db.shop · checked Mar 19, 2026
¿Te ha afectado esta página web?
Si ingresó credenciales de cuenta, información personal o de pago, o descargó un archivo de este dominio, tome medidas inmediatas. A continuación encontrará recursos que le ayudarán a informar el incidente y protegerse.
Informa a las autoridades locales
Seleccione su país para obtener contactos oficiales de cibercrimen o crear un borrador de queja →.
Comprobar cualquier dominio
Análisis de amenazas utilizando listas de bloqueo almacenadas, WHOIS, DNS y evidencia de escaneo público
Escanear ahoraDenunciar un intento de phishing
Envía los dominios sospechosos a nuestra base de datos de amenazas: protege a la comunidad
DenunciarFlujo de amenazas en tiempo real
Informes de phishing recientes y cambios de disponibilidad observados
MonitorizarMantente informado, mantente a salvo
Supervisa las amenazas en tiempo real o impugna esta entrada si crees que se trata de un falso positivo.