raydium[.]firebid[.]xyz
“Swap Raydium”
raydium.firebid.xyz — Contenido no disponible (HTTP 502). Suplantación de marca: Raydium; Tipo de estafa: Wallet/seed Phishing. Resumen de las pruebas: VirusTotal 0 detections (engine total unavailable); PhishDestroy score 45/100. Registrador: Go Daddy.
El análisis detallado de PhishDestroy AI se mantiene en inglés para conservar el registro forense original.
Analysis of the domain raydium.firebid.xyz indicates it was actively involved in a wallet seed phishing campaign targeting users of the Raydium decentralized exchange. The domain, registered on April 11, 2025, through Go Daddy, LLC, resolved to the IP address 54.192.51.87, hosted under Amazon.com, Inc. (AS16509) in the United States. Infrastructure analysis reveals the use of AWS nameservers, specifically ns-1141.awsdns-14.org, ns-1977.awsdns-55.co.uk, ns-229.awsdns-28.com, and ns-652.awsdns, which is consistent with cloud-based phishing operations. The domain lacked an SSL certificate, increasing the likelihood of interception of sensitive data transmitted to the site.
The page title, 'Swap Raydium,' directly aligns with the identified scam type of wallet or seed phishing, suggesting the site was designed to deceive users into entering cryptocurrency wallet credentials or recovery phrases. As of the report date, the domain has been taken offline, though its prior operational status was confirmed by its presence on one security blocklist, PhishDestroy. No detections were recorded by the 95 vendors that scanned the domain on VirusTotal, though the absence of detections does not confirm the domain's safety or legitimacy. Defenders are advised to treat this domain as malicious based on its registration details, hosting infrastructure, and inclusion on a security blocklist.
Network-level blocking of the IP address 54.192.51.87 and monitoring for related domains registered through Go Daddy, LLC, or utilizing AWS nameservers may mitigate further risks. Given the domain's offline status, retrospective analysis of logs for connections to 54.192.51.87 or raydium.firebid.xyz is recommended to identify potential compromise. The exact content and functionality of the phishing page remain unanalyzed, though the combination of the page title, scam type, and brand target strongly suggests a focus on cryptocurrency theft.
Proceso de respuesta ante amenazas Pipeline
Estado de la lista de bloqueados pública
Captura guardada
Inteligencia de dominios
Detalles técnicosDNS, SAN de SSL, marcas de tiempo
ICANN OVERSIGHT
Registration: firebid.xyz
Acreditación y contexto RAA
Acreditación y contexto RAA
Registrar accreditation and DNS abuse obligations
For the registrable domain firebid.xyz behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Inteligencia forense
Análisis de VirusTotal
Datos y informes externos
¿Te ha afectado esta página web?
Si ingresó credenciales de cuenta, información personal o de pago, o descargó un archivo de este dominio, tome medidas inmediatas. A continuación encontrará recursos que le ayudarán a informar el incidente y protegerse.
Informa a las autoridades locales
Seleccione su país para obtener contactos oficiales de cibercrimen o crear un borrador de queja →.
Comprobar cualquier dominio
Análisis de amenazas utilizando listas de bloqueo almacenadas, WHOIS, DNS y evidencia de escaneo público
Escanear ahoraDenunciar un intento de phishing
Envía los dominios sospechosos a nuestra base de datos de amenazas: protege a la comunidad
DenunciarFlujo de amenazas en tiempo real
Informes de phishing recientes y cambios de disponibilidad observados
MonitorizarMantente informado, mantente a salvo
Supervisa las amenazas en tiempo real o impugna esta entrada si crees que se trata de un falso positivo.