evmbulksender[.]com
“EVMbulkSender.com – Multi-chain EVM-based Bulk Sender | FAQ”
Analysis of evmbulksender.com shows a newly registered domain created on February 21, 2026 that has been used for wallet or seed phishing. The site resolves to IP address 104.21.89.148, which belongs to Cloudflare, Inc. (AS13335) and is geolocated in the United States. No SSL certificate was observed, indicating the site operated without HTTPS. The registrar listed is Hello Internet Corp, and the domain is served by the nameservers ns100.webnic.cc and ns101.webnic.cc.
Reputation scoring from Gridinsoft assigns a trust score of 0 out of 100, while Scamadviser reports a score of 20 out of 100, both reflecting a highly malicious posture. The domain appears on four external security blocklists and is explicitly blocked by PhishDestroy, MetaMask, ScamSniffer, and SEAL, confirming its classification as a phishing vector. AlienVault OTX has indexed the domain in one threat‑intel pulse, and VirusTotal scans indicate that two of ninety‑three security vendors flagged the site as malicious. The page title retrieved, "EVMbulkSender.com – Multi-chain EVM-based Bulk Sender | FAQ," aligns with the advertised service and supports the wallet/seed phishing claim.
Current status is offline, suggesting the active hosting has been taken down, but the infrastructure footprint (Cloudflare IP, known blocklists) remains a reusable asset for potential re‑deployment. Defenders should continue to monitor the domain’s DNS resolution for any re‑activation, ensure it is added to internal blocklists, and correlate any outbound traffic to the listed IP with credential‑theft detection rules. Given the low trust scores, multiple blocklist listings, and confirmed vendor detections, the domain should be treated as a high‑confidence malicious indicator and excluded from any trusted web‑access policies.
Enregistrement du signalement transmis
Instantané des preuves transmises
- Envoyé
- Entrées du registre
- 1
- ID du dossier
PD-20260124-BA455D- Artefact PDF
- Preuve PDF
Fondement juridique
Texte intégral des preuves
Acceptable Use Policy (AUP): The domain evmbulksender.com is engaged in phishing activities, which is a clear violation of your AUP prohibiting illegal activities, fraud, and deception.
Terms of Service (TOS): The continued operation of this domain constitutes a breach of your TOS, which reserves the right to suspend or terminate services for any violation, particularly those involving fraudulent activities.
Applicable Laws (Unknown):
Computer Fraud and Abuse Act (CFAA): This U.S. law prohibits unauthorized access to computers and networks, which is applicable to phishing schemes that deceive individuals into providing sensitive information.
Wire Fraud (18 U.S.C. § 1343): This federal law criminalizes schemes to defraud individuals or entities using electronic communications, including phishing.
CAN-SPAM Act (15 U.S.C. § 7701): This law regulates commercial email and prohibits deceptive practices in email marketing, which includes phishing attempts.
Regulatory Note: Failure to take immediate action against evmbulksender.com may expose your organization to legal liability and regulatory scrutiny. Non-compliance with your own policies and applicable laws could result in significant penalties.
Signaux de sécurité
Processus de réponse aux menaces Pipeline
Couverture des listes de blocage
10 sources · synchronisées le 10/08/2026
Chronologie de détection
Observations enregistrées par ordre chronologique.
-
Observation enregistrée
Observation enregistrée : alive → dead
-
Cloudflare Radar
Cloudflare Radar : observé pour la première fois comme https://radar.cloudflare.com/scan/a975d045-d68e-4101-b70f-95999dfddac5
Capture enregistrée
Informations sur les domaines
Détails techniquesDNS, noms TLS et horodatages
ICANN OVERSIGHT
Contexte de l’accréditation et du RAA
Contexte de l’accréditation et du RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Analyse VirusTotal
Ce site vous a-t-il affecté ?
Si vous avez saisi des informations d'identification de compte, des informations personnelles ou de paiement, ou téléchargé un fichier à partir de ce domaine, agissez immédiatement. Vous trouverez ci-dessous des ressources pour vous aider à signaler l'incident et à vous protéger.
Signalez-le à vos autorités locales
Sélectionnez votre pays pour obtenir contacts officiels en matière de cybercriminalité ou créer un projet de plainte →.
Vérifier n'importe quel domaine
Analyse des menaces à l'aide de listes de blocage stockées, de WHOIS, de DNS et de preuves d'analyse publique
Scanner maintenantSignaler une tentative d'hameçonnage
Signalez les domaines suspects à notre base de données des menaces — protégez la communauté
SignalerFlux d'alertes en temps réel
Rapports de phishing récents et changements de disponibilité observés
SurveillerRestez informés, restez en sécurité
Surveillez les menaces en temps réel ou signalez cette alerte si vous pensez qu'il s'agit d'un faux positif