shadowpay[.]at
Análisis de phishing y seguridad de shadowpay.at
“ShadowPay - Instant CS2 Skins Trading”
shadowpay.at — Encubierto · accesible (HTTP 502). Tipo de estafa: Crypto Drainer. Resumen de las pruebas: VirusTotal 0/94; cloaking observed; PhishDestroy score 25/100. Registrador: Hosting concepts.
El análisis detallado de PhishDestroy AI se mantiene en inglés para conservar el registro forense original.
PhishDestroy flagged shadowpay.at as a generic phishing domain currently under investigation for hosting a cryptocurrency drainer kit. This domain mimics legitimate cryptocurrency services to deceive users into connecting wallets or entering credentials, which are then exploited to siphon digital assets. No specific brand or drainer kit variant has been confirmed yet, but the domain’s behavior aligns with known theft patterns targeting unsuspecting cryptocurrency users.
Exact technical indicators for shadowpay.at include a VirusTotal detection score of 0/95, indicating no current antivirus or security vendor flags despite its malicious intent. The domain is registered through Hosting Concepts B.V. via Registrar.eu, resolving to IP 188.114.97.3. Notably, it holds an SSL certificate issued by Google Trust Services, which may be leveraged to lend false legitimacy to phishing pages. The domain is actively resolving and remains unblocked by major threat intelligence platforms, increasing exposure to potential victims. While the creation date is unverified in available data, its active status and lack of detections suggest it is a recently deployed threat.
As of the latest assessment, shadowpay.at remains an active threat with a status of 'under_investigation' and a risk level yet to be finalized. PhishDestroy recommends immediate blocking of the domain and IP address 188.114.97.3 at the network perimeter to mitigate exposure. Users should avoid accessing the domain and report any interactions to their security teams. Remaining risk hinges on further analysis of its drainer kit and potential connections to broader phishing campaigns. The absence of detections and the use of a Google-issued SSL certificate underscore the need for heightened scrutiny and proactive threat hunting to prevent cryptocurrency theft.
Proceso de respuesta ante amenazas Pipeline
Estado de la lista de bloqueados pública
Tecnologías · 3 identified
Performance monitoring tool that measures website speed from real users.
www.cloudflare.comWeb infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
Análisis de VirusTotal
Evidencias archivadas
Análisis del rendimiento del sitio
Google PageSpeed Insights — mobile performance audit of shadowpay.at · checked Apr 15, 2026
Datos y informes externos
¿Te ha afectado esta página web?
Si ingresó credenciales de cuenta, información personal o de pago, o descargó un archivo de este dominio, tome medidas inmediatas. A continuación encontrará recursos que le ayudarán a informar el incidente y protegerse.
Informa a las autoridades locales
Seleccione su país para obtener contactos oficiales de cibercrimen o crear un borrador de queja →.
Comprobar cualquier dominio
Análisis de amenazas utilizando listas de bloqueo almacenadas, WHOIS, DNS y evidencia de escaneo público
Escanear ahoraDenunciar un intento de phishing
Envía los dominios sospechosos a nuestra base de datos de amenazas: protege a la comunidad
DenunciarFlujo de amenazas en tiempo real
Informes de phishing recientes y cambios de disponibilidad observados
MonitorizarMantente informado, mantente a salvo
Supervisa las amenazas en tiempo real o impugna esta entrada si crees que se trata de un falso positivo.