learn-dydx-trade[.]typedream[.]app
“404: This page could not be found.”
learn-dydx-trade.typedream.app — Contenido no disponible. Suplantación de marca: dYdX; Tipo de estafa: Crypto Scam. Resumen de las pruebas: VirusTotal 16/93 (ADMINUSLabs, ChainPatrol, alphaMountain.ai, BitDefender, CRDF); CF Radar malicious; PhishDestroy score 95/100. Registrador: Squarespace Domains II.
El análisis detallado de PhishDestroy AI se mantiene en inglés para conservar el registro forense original.
Analysis of learn-dydx-trade.typedream.app shows a newly registered domain created on 21 February 2026 that is currently offline and returns a 404 HTTP status. The site was hosted behind Cloudflare (ASN 13335) and resolves to the IP address 188.114.97.3 located in the United States. SSL termination is provided by Google Trust Services under the WE1 certificate, indicating the use of Google Cloud infrastructure. Fingerprinting of the web stack reveals Node.js, React, Next.js, Google Cloud Trace, Google Cloud CDN and Cloudflare Browser Insights, all typical of modern JavaScript‑heavy applications. Registration was performed through Squarespace Domains II LLC, a known registrar for many short‑lived abuse campaigns.
The domain is explicitly listed as impersonating the dYdX brand and is classified as a crypto‑related scam. VirusTotal has recorded detections from 16 of 93 scanning engines, and the domain appears on at least one external blocklist, namely PhishDestroy, which has already blocked it. No additional threat‑intel feeds such as OTX or Google Safe Browsing were referenced in the supplied data. Given the combination of brand impersonation, a recent creation date, active detections by multiple vendors, and a hosted infrastructure that can be rapidly provisioned, the domain should be treated as a confirmed malicious actor targeting users of the dYdX platform.
Defenders should add the domain to internal block lists, update DNS filtering rules to deny resolution, and monitor for any related C2 infrastructure that may share the same IP or Cloudflare configuration. Since the site currently returns a 404 page, any future change in HTTP response should be re‑examined promptly. Analysts should also watch for new domains registered by the same registrar that contain the “dydx” keyword, as the pattern suggests an automated naming scheme. Continuous correlation with threat‑intel feeds will help capture any resurgence of the campaign.
Inteligencia de seguridad de red
Proceso de respuesta ante amenazas Pipeline
Estado de la lista de bloqueados pública
Tecnologías · 10 identified
Node.js is an open-source, cross-platform, JavaScript runtime environment that executes JavaScript code outside a web browser.
nodejs.org 100 % de confianzaReact is an open-source JavaScript library for building user interfaces or UI components.
reactjs.org 100 % de confianzaNext.js is a React framework for developing single page Javascript applications.
nextjs.org 100 % de confianzaGoogle Cloud Trace is a distributed tracing system that collects latency data from applications and displays it in the Google Cloud Console.
cloud.google.com 100 % de confianzaCloud CDN uses Google's global edge network to serve content closer to users.
cloud.google.com 100 % de confianzaCloudflare Browser Insights is a tool that measures the performance of websites from the perspective of users.
www.cloudflare.com 100 % de confianzaCloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com 100 % de confianzaHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100 % de confianzaAnálisis de VirusTotal
Análisis de la configuración del sitio
Datos y informes externos
¿Te ha afectado esta página web?
Si ingresó credenciales de cuenta, información personal o de pago, o descargó un archivo de este dominio, tome medidas inmediatas. A continuación encontrará recursos que le ayudarán a informar el incidente y protegerse.
Informa a las autoridades locales
Seleccione su país para obtener contactos oficiales de cibercrimen o crear un borrador de queja →.
Comprobar cualquier dominio
Análisis de amenazas utilizando listas de bloqueo almacenadas, WHOIS, DNS y evidencia de escaneo público
Escanear ahoraDenunciar un intento de phishing
Envía los dominios sospechosos a nuestra base de datos de amenazas: protege a la comunidad
DenunciarFlujo de amenazas en tiempo real
Informes de phishing recientes y cambios de disponibilidad observados
MonitorizarMantente informado, mantente a salvo
Supervisa las amenazas en tiempo real o impugna esta entrada si crees que se trata de un falso positivo.