evmnet[.]cc
The domain evmnet.cc was registered on May 16, 2026 through NICENIC INTERNATIONAL GROUP CO., LIMITED and is presently resolved to the Cloudflare‑hosted address 104.21.94.244, located in Canada. The site presents a valid HTTPS certificate issued by Let’s Encrypt (E7) and returns HTTP 200 responses, indicating an operational web server. Its authoritative name servers are johnny.ns.cloudflare.com and rayne.ns.cloudflare.com, confirming the use of Cloudflare’s DNS infrastructure.
Infrastructure analysis shows a low Gridinsoft trust score of 23 out of 100, and the domain appears on three independent security blocklists. It has been explicitly blocked by multiple anti‑phishing filters, including PhishDestroy, MetaMask, and SEAL, suggesting that known malicious payloads or credential‑harvesting pages have been observed. The domain also surfaces in a single AlienVault OTX pulse, providing additional community‑level corroboration of its malicious use.
VirusTotal scans have flagged evmnet.cc in eight out of ninety‑five antivirus engines, reinforcing the suspicion of malicious activity despite a modest detection rate. The combination of a recent registration date, active HTTPS service, and presence on reputable blocklists aligns with behaviors typical of credential‑stealing operations targeting cryptocurrency or financial services. However, the exact phishing template, targeted brands, or victim demographics remain unclear from the publicly available data.
Defenders should prioritize adding evmnet.cc to network deny lists and enforce DNS‑level blocking to prevent client access. Continuous monitoring of the associated IP address and any newly observed sub‑domains is advisable, as the underlying Cloudflare infrastructure can be repurposed for fast‑flux hosting. Incident response teams should also correlate internal logs for any outbound connections to 104.21.94.244 and investigate potential credential capture attempts originating from this endpoint.
Signaux de sécurité
Renseignements sur la sécurité réseau Registrar context
Processus de réponse aux menaces Pipeline
Couverture des listes de blocage
10 sources · synchronisé le 10/08/2026
Chronologie de détection
Observations enregistrées par ordre chronologique.
-
Disponibilité
Disponibilité : observé pour la première fois comme unknown
993d00c35140 -
Disponibilité
Disponibilité : unknown → redirected
718da7f3dbec -
Disponibilité
Disponibilité : redirected → unknown
b8fab9cf4018 -
Disponibilité
Disponibilité : unknown → redirected
182246c9bea0 -
Disponibilité
Disponibilité : redirected → unknown
7cebcfd4071c -
Disponibilité
Disponibilité : unknown → redirected
1f6835537d1f -
Disponibilité
Disponibilité : redirected → unknown
ca255b61650a -
Disponibilité
Disponibilité : unknown → redirected
779ee49174a2 -
Disponibilité
Disponibilité : redirected → unknown
d8f7d37d7f95 -
Disponibilité
Disponibilité : unknown → redirected
8d588aae1884
Informations sur les domaines
Détails techniquesDNS, noms TLS et horodatages
Analyse VirusTotal
Analyse de la configuration du site
Ce site vous a-t-il affecté ?
Si vous avez saisi des informations d'identification de compte, des informations personnelles ou de paiement, ou téléchargé un fichier à partir de ce domaine, agissez immédiatement. Vous trouverez ci-dessous des ressources pour vous aider à signaler l'incident et à vous protéger.
Signalez-le à vos autorités locales
Sélectionnez votre pays pour obtenir contacts officiels en matière de cybercriminalité ou créer un projet de plainte →.
Vérifier n'importe quel domaine
Analyse des menaces à l'aide de listes de blocage stockées, de WHOIS, de DNS et de preuves d'analyse publique
Scanner maintenantSignaler une tentative d'hameçonnage
Signalez les domaines suspects à notre base de données des menaces — protégez la communauté
SignalerFlux d'alertes en temps réel
Rapports de phishing récents et changements de disponibilité observés
SurveillerRestez informés, restez en sécurité
Surveillez les menaces en temps réel ou signalez cette alerte si vous pensez qu'il s'agit d'un faux positif