xn--monshot-2uc[.]net
“xn--monshot-2uc.net | 522: Connection timed out”
xn--monshot-2uc.net — No verificado. Resumen de las pruebas: VirusTotal 11/91 (alphaMountain.ai, BitDefender, Chong Lua Dao, CyRadar, Forcepoint ThreatSeeker); Spamhaus DBL_PHISH; 1 external blocklist match (ScamSniffer); PhishDestroy score 88/100. Registrador: NiceNIC.
El análisis detallado de PhishDestroy AI se mantiene en inglés para conservar el registro forense original.
This domain, xn--monshot-2uc.net, is identified as a crypto wallet phishing resource targeting users through deceptive infrastructure. Analysis indicates the site mimics legitimate cryptocurrency platforms to harvest wallet credentials and private keys. No direct association with known drainer kits has been confirmed, though the domain's Punycode format (xn--) suggests an attempt to obfuscate its true nature and evade casual detection. The threat category is classified as generic_phishing with an elevated risk level due to its financial fraud objectives. Infrastructure analysis reveals the domain was registered on February 21, 2026, through NiceNIC International Group Co., Limited. As of the latest scan, VirusTotal reports 9 out of 95 security vendors flagging the domain as malicious. The domain appears on two independent security blocklists and is actively blocked by multiple fraud detection systems. No associated IP address or Google Safe Browsing (GSB) listing was recorded prior to takedown, limiting further network-level attribution. The page title, displaying a 522 connection timeout, suggests the hosting infrastructure was either disrupted or intentionally disabled. The domain is currently offline, reducing immediate exposure to end users. However, the registration remains active, and the infrastructure could be reactivated with minimal effort. The registrar, NiceNIC International Group Co., Limited, has not publicly disclosed any enforcement actions against the domain. Users who interacted with the site prior to takedown are advised to revoke any connected wallet permissions and monitor accounts for unauthorized transactions. Continued vigilance is recommended, as similar domains may emerge using comparable obfuscation techniques.
Inteligencia de seguridad de red Registrar context
Proceso de respuesta ante amenazas Pipeline
Estado de la lista de bloqueados pública
Captura guardada
Inteligencia de dominios
Detalles técnicosDNS, SAN de SSL, marcas de tiempo
ICANN OVERSIGHT
Acreditación y contexto RAA
Acreditación y contexto RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Latest Classified Outcome 2026-08-20 02:50:15 UTC
Tecnologías · 2 identified
Web infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
Análisis de VirusTotal
Datos y informes externos
¿Te ha afectado esta página web?
Si ingresó credenciales de cuenta, información personal o de pago, o descargó un archivo de este dominio, tome medidas inmediatas. A continuación encontrará recursos que le ayudarán a informar el incidente y protegerse.
Informa a las autoridades locales
Seleccione su país para obtener contactos oficiales de cibercrimen o crear un borrador de queja →.
Comprobar cualquier dominio
Análisis de amenazas utilizando listas de bloqueo almacenadas, WHOIS, DNS y evidencia de escaneo público
Escanear ahoraDenunciar un intento de phishing
Envía los dominios sospechosos a nuestra base de datos de amenazas: protege a la comunidad
DenunciarFlujo de amenazas en tiempo real
Informes de phishing recientes y cambios de disponibilidad observados
MonitorizarMantente informado, mantente a salvo
Supervisa las amenazas en tiempo real o impugna esta entrada si crees que se trata de un falso positivo.