dexweb-defi[.]vip
“404 Not Found”
Résumé des preuves
Analysis of dexweb-defi.vip indicates that the domain was registered on May 30 2025 through Dynadot LLC and subsequently used in a crypto‑drainer campaign. The domain resolves to 172.67.146.34, an address owned by Cloudflare (AS13335) located in the United States. Both clyde.ns.cloudflare.com and paloma.ns.cloudflare.com are listed as authoritative name servers, confirming the Cloudflare front‑end. The site presented a 404 Not Found page title at the time of capture, and its SSL certificate was issued by Google Trust Services under the WE1 root, demonstrating a valid TLS chain. Detection services flagged the domain: 15 of 93 vendors on VirusTotal reported it as malicious, two independent blocklists listed it, and Google Safe Browsing classified it as social engineering.
Additional security products PhishDestroy and ScamSniffer have also blocked the domain. The Gridinsoft trust score of 0/100 reflects an extremely low reputation. The observed technology stack includes Cloudflare services and HTTP/3 support, which can be leveraged to obfuscate traffic. The current status is offline, which may be temporary or a takedown.
While the available data confirms the domain’s involvement in a crypto‑drainer operation, no further details about the specific payload, victim interaction flow, or associated cryptocurrency addresses have been uncovered. Defenders should continue to monitor the IP 172.67.146.34 for any resurgence of malicious activity, enforce deny‑list rules for the domain and its IP in web filtering solutions, and propagate the detection indicators to threat‑intel sharing platforms. Network sensors should be tuned to alert on TLS connections to the Google Trust Services‑issued certificate presented by this domain, and any outbound requests to the Cloudflare edge nodes should be inspected for anomalous patterns consistent with crypto‑drainer traffic.
Data Coverage
Processus de réponse aux menaces Pipeline
Couverture des listes de blocage
10 sources externes surveillées · instantané du 12/08/2026
9 sources externes surveillées Aucune correspondance
Capture enregistrée
Informations sur les domaines
Détails techniquesDNS, noms TLS et horodatages
ICANN OVERSIGHT
Contexte de l’accréditation et du RAA
Contexte de l’accréditation et du RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Analyse VirusTotal
Analyse des performances du site
Google PageSpeed Insights — mobile performance audit of dexweb-defi.vip · checked Mar 2, 2026
Ce site vous a-t-il affecté ?
Si vous avez saisi des informations d'identification de compte, des informations personnelles ou de paiement, ou téléchargé un fichier à partir de ce domaine, agissez immédiatement. Vous trouverez ci-dessous des ressources pour vous aider à signaler l'incident et à vous protéger.
Signalez-le à vos autorités locales
Sélectionnez votre pays pour obtenir contacts officiels en matière de cybercriminalité ou créer un projet de plainte →.
Vérifier n'importe quel domaine
Analyse des menaces à l'aide de listes de blocage stockées, de WHOIS, de DNS et de preuves d'analyse publique
Scanner maintenantSignaler une tentative d'hameçonnage
Signalez les domaines suspects à notre base de données des menaces — protégez la communauté
SignalerFlux d'alertes en temps réel
Rapports de phishing récents et changements de disponibilité observés
SurveillerRestez informés, restez en sécurité
Surveillez les menaces en temps réel ou signalez cette alerte si vous pensez qu'il s'agit d'un faux positif