n8n[.]consensys-digital[.]cloud
“n8n.io - Workflow Automation”
Resumen de las pruebas
The domain n8n.consensys-digital.cloud was registered on February 21, 2026 through Hostinger Operations, UAB and is delegated to the parking nameservers ns1.dns-parking.com and ns2.dns-parking.com. DNS resolution points to the IPv4 address 168.231.79.222, which belongs to AS47583 Hostinger International Limited and is geolocated in Great Britain. No TLS certificate is presented for the host, indicating that HTTPS is not available and that any traffic to the site would be unencrypted. The site’s HTTP response returned a page title of "n8n.io - Workflow Automation," matching the legitimate n8n brand, suggesting an attempt to masquerade as the authentic service.
VirusTotal scans have recorded three positive detections out of ninety‑five security vendors, providing independent confirmation that the domain is associated with malicious activity. The domain is currently listed on three public blocklists—PhishDestroy, MetaMask, and SEAL—and has been flagged by additional security blocklists, reinforcing its reputation as a phishing vector. The host is presently taken offline, which may be the result of takedown actions or automated mitigation.
While the page content has not been examined directly, the combination of brand‑matching page title, lack of TLS, host‑based detection, and blocklist listings constitute strong evidence of a generic phishing operation aimed at credential harvesting for n8n.io users. Defenders should continue to block the domain at network perimeter and DNS layers, monitor for any re‑appearance of the host on the same IP range, and advise users to verify URLs before entering credentials. Ongoing surveillance of the associated IP address and related AS is recommended to detect potential repurposing for further malicious campaigns.
Instantánea de evidencia enviada
- Enviado
- Registros del libro
- 1
- ID del caso
PD-20260218-124405- Título de la página capturada
- n8n.io - Workflow Automation
- Artefacto PDF
- Evidencia en PDF
Fundamento jurídico
Texto completo de la evidencia
Section 3.1 of the Acceptable Use Policy: The domain n8n.consensys-digital.cloud is being used for phishing activities, which constitutes a clear violation of the prohibition against illegal activities and deception.
Section 5.2 of the Terms of Service: The registrar reserves the right to suspend or terminate services for any violations, including those related to fraud and phishing, which are evident in the activities associated with this domain.
Applicable Laws (Unknown):
Computer Fraud and Abuse Act (CFAA) - 18 U.S.C. § 1030: This federal law prohibits unauthorized access to computers and networks, including activities that involve phishing.
Wire Fraud Statute - 18 U.S.C. § 1343: This law addresses fraudulent schemes that involve electronic communications, which is applicable to phishing activities that deceive individuals for financial gain.
CAN-SPAM Act - 15 U.S.C. § 7701: This act regulates commercial email and prohibits deceptive practices, including those associated with phishing.
Regulatory Note: Failure to take appropriate action against this domain may result in regulatory scrutiny and potential liability under applicable laws. Immediate suspension is advised to mitigate risks associated with non-compliance.
Data Coverage
Inteligencia de seguridad de red
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Private YARA rules | n8n.consensys-digital.cloud/assets/worker-civwfg3a.js |
audit | Hunting_JS_WebAssembly |
| Quad9 DNS | n8n.consensys-digital.cloud |
malicious | Sinkholed |
Proceso de respuesta ante amenazas Pipeline
Cobertura de listas de bloqueo
10 fuentes externas supervisadas · instantánea del 13/08/2026
8 fuentes externas supervisadas Sin coincidencias
Cronología de detección
-
Cloudflare Radar
Análisis de Cloudflare Radar almacenado · Abrir análisis
Captura guardada
Inteligencia de dominios
Detalles técnicosDNS, nombres TLS y marcas de tiempo
ICANN OVERSIGHT
Registration: consensys-digital.cloud
Acreditación y contexto RAA
Acreditación y contexto RAA
Registrar accreditation and DNS abuse obligations
For the registrable domain consensys-digital.cloud behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Análisis de VirusTotal
¿Te ha afectado esta página web?
Si ingresó credenciales de cuenta, información personal o de pago, o descargó un archivo de este dominio, tome medidas inmediatas. A continuación encontrará recursos que le ayudarán a informar el incidente y protegerse.
Informa a las autoridades locales
Seleccione su país para obtener contactos oficiales de cibercrimen o crear un borrador de queja →.
Comprobar cualquier dominio
Análisis de amenazas utilizando listas de bloqueo almacenadas, WHOIS, DNS y evidencia de escaneo público
Escanear ahoraDenunciar un intento de phishing
Envía los dominios sospechosos a nuestra base de datos de amenazas: protege a la comunidad
DenunciarFlujo de amenazas en tiempo real
Informes de phishing recientes y cambios de disponibilidad observados
MonitorizarMantente informado, mantente a salvo
Supervisa las amenazas en tiempo real o impugna esta entrada si crees que se trata de un falso positivo.