MALICIOUS — CRITICAL
Análisis de phishing y seguridad de bl0ckdaq.network
bl0ckdaq[.]
Security analysis of bl0ckdaq.network covers observed phishing indicators, infrastructure evidence, current status, and defensive guidance.
- VirusTotal
- 9/95
- Blocklists
- 2 · MetaMask, SEAL
- Disponibilidad
- Accesible · acceso restringido · HTTP 403
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
bl0ckdaq.network — Accesible · acceso restringido (HTTP 403). Suplantación de marca: Across; Tipo de estafa: Fake Airdrop. Resumen de las pruebas: VirusTotal 9/95 (ADMINUSLabs, alphaMountain.ai, CRDF, CyRadar, Fortinet); URLScan malicious verdict; Spamhaus DBL_PHISH; 2 external blocklist matches (MetaMask, SEAL); CF Radar malicious; PhishDestroy score 85/100. Registrador: NiceNIC.
El análisis detallado de PhishDestroy AI se mantiene en inglés para conservar el registro forense original.
Evidence Analysis
The domain bl0ckdaq.network was registered on 21 February 2026 through NiceNIC International Group Co., Limited and is currently resolved to the Cloudflare address 188.114.97.3, which belongs to ASN 13335 (Cloudflare, Inc.) located in the United States. The authoritative name servers bayan.ns.cloudflare.com and marge.ns.cloudflare.com confirm that the domain is hosted behind Cloudflare’s edge network, and the TLS certificate presented is issued by Google Trust Services under the WE1 root, indicating a valid certificate chain. HTTP analysis shows the site responded with status code 403 and employs HSTS, HTTP/3, and other Cloudflare‑provided security headers. The page title retrieved from the site reads “BlockDAG – Ground‑Breaking Crypto Presale 2026”, and the underlying phishing kit is identified as a Token Presale package, suggesting an attempt to lure cryptocurrency investors.
VirusTotal scans report nine detections out of ninety‑five vendors, and the domain appears on three external blocklists. It has also been flagged by PhishDestroy, MetaMask, and SEAL, all of which have taken active mitigation steps. The campaign is classified as brand impersonation with an elevated risk rating, though the specific victim brand is not disclosed beyond a generic “across” label.
At the time of reporting the site is offline, which limits further behavioural observation. Defenders should continue to block the domain at DNS and proxy layers, monitor the associated IP address for any re‑use, and update endpoint and browser security solutions with the latest indicator sets. Additional investigation of the Token Presale kit may reveal reusable components that could appear in future campaigns.
Stored source results
Recorded verdicts and infrastructure observations for this domain.
Cobertura de los datos12 recorded checks
Inteligencia de seguridad de red Registrar context
Proceso de respuesta ante amenazas Pipeline
Estado de la lista de bloqueados pública
Captura guardada
Inteligencia de dominios
Detalles técnicosDNS, SAN de SSL, marcas de tiempo
ICANN OVERSIGHT
Acreditación y contexto RAA
Acreditación y contexto RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Latest Classified Outcome 2026-08-09 01:49:57 UTC
Tecnologías · 3 identified
HTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org 100 % de confianzaCloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com 100 % de confianzaHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100 % de confianzaAnálisis de VirusTotal
Evidencias archivadas
Datos y informes externosIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
Si ingresó credenciales de cuenta, información personal o de pago, o descargó un archivo de este dominio, tome medidas inmediatas. A continuación encontrará recursos que le ayudarán a informar el incidente y protegerse.
Informa a las autoridades locales
Seleccione su país para obtener contactos oficiales de cibercrimen o crear un borrador de queja →.