hickory[.]website
Análisis de phishing y seguridad de hickory.website
“TRON Wallet Integration Example”
hickory.website — Contenido no disponible (HTTP 502). Suplantación de marca: Binance; Tipo de estafa: Crypto Scam. Resumen de las pruebas: VirusTotal 10/93 (ADMINUSLabs, alphaMountain.ai, BitDefender, CRDF, CyRadar); URLScan malicious verdict; 3 external blocklist matches (Polkadot, Enkrypt, Codeesura); PhishDestroy score 80/100.
El análisis detallado de PhishDestroy AI se mantiene en inglés para conservar el registro forense original.
This domain, hickory.website, was identified as a high-risk crypto scam impersonating Binance, with infrastructure analysis confirming its malicious intent prior to being taken offline. Registered on February 21, 2026, the domain resolved to IP 66.29.146.168, hosted on AS22612 (Namecheap, Inc.) in the United States. The SSL certificate, issued by Sectigo Public Server Authentication CA (DV R36), provided no additional trust signals, as Domain Validation certificates are routinely abused in phishing campaigns. The page title, 'TRON Wallet Integration Example,' suggests the scam targeted users of TRON-based cryptocurrency wallets, aligning with the broader pattern of Binance brand impersonation for fraudulent crypto transactions. Security vendors and blocklists flagged the domain aggressively: PhishDestroy, Polkadot, Enkrypt, and Codeesura all blocked it, and it appeared on four independent security blocklists.
While VirusTotal recorded 10 detections out of 93 vendors, this partial coverage is consistent with domains that evade initial scans or are reported after partial exposure. Gridinsoft assigned a trust score of 0/100, reinforcing its classification as malicious. No evidence links this domain to a known phishing kit, and the exact content beyond the page title remains unanalyzed due to its offline status. Defenders should treat this domain as confirmed malicious infrastructure. The IP (66.29.146.168) and hosting provider (Namecheap) are recurrent in phishing operations, warranting monitoring for re-registration or IP reuse.
The SSL issuer (Sectigo) is not inherently suspicious, but the DV certificate type offers no organizational validation. Given the domain’s short lifespan and rapid takedown, it likely operated as part of a larger campaign; defenders should cross-reference the IP, registrar, and brand impersonation (Binance) in logs for related activity. No Safe Browsing or OTX data was provided, so additional context on distribution methods (e.g.
Proceso de respuesta ante amenazas Pipeline
Estado de la lista de bloqueados pública
Inteligencia forense
Análisis de VirusTotal
Datos y informes externos
¿Te ha afectado esta página web?
Si ingresó credenciales de cuenta, información personal o de pago, o descargó un archivo de este dominio, tome medidas inmediatas. A continuación encontrará recursos que le ayudarán a informar el incidente y protegerse.
Informa a las autoridades locales
Seleccione su país para obtener contactos oficiales de cibercrimen o crear un borrador de queja →.
Comprobar cualquier dominio
Análisis de amenazas utilizando listas de bloqueo almacenadas, WHOIS, DNS y evidencia de escaneo público
Escanear ahoraDenunciar un intento de phishing
Envía los dominios sospechosos a nuestra base de datos de amenazas: protege a la comunidad
DenunciarFlujo de amenazas en tiempo real
Informes de phishing recientes y cambios de disponibilidad observados
MonitorizarMantente informado, mantente a salvo
Supervisa las amenazas en tiempo real o impugna esta entrada si crees que se trata de un falso positivo.