gainz[.]entry-cryptolist[.]app
“CRYPTOLIST”
gainz.entry-cryptolist.app — Contenu indisponible. Résumé des preuves: VirusTotal 14/91 (ADMINUSLabs, BitDefender, Chong Lua Dao, CRDF, CyRadar); PhishDestroy score 92/100.
L’analyse détaillée de PhishDestroy AI reste en anglais afin de préserver le relevé forensique original.
This domain, gainz.entry-cryptolist.app, is currently classified as a generic phishing campaign and remains active as of the report date, 29 July 2026. Infrastructure analysis shows that the name resolves to the IPv4 address 188.114.97.3. The host is listed by the blocklist service PhishDestroy, indicating that the domain has been deliberately taken down by that protective platform. VirusTotal records show that 14 of 91 security‑vendor scanners flag the domain as malicious, providing modest but consistent detection across independent tools.
Additionally, the domain appears on one external security blocklist, reinforcing the view that it is considered unsafe by at least one third‑party threat‑intelligence source. Public DNS data for the domain is incomplete; the authoritative nameservers could not be retrieved (NS_NOT_FOUND), which limits the ability to assess registrar details, name‑server hierarchy, or potential use of fast‑flux techniques. No SSL/TLS certificate information is available, and there are no published HTTP response codes, page titles, or Safe Browsing verdicts linked to the domain in the current intelligence set. Consequently, the visual or functional characteristics of the hosted site remain unknown, and any attribution to a specific brand or lure cannot be confirmed.
At present, no evidence of a valid TLS certificate, redirect chain, or content fingerprint has been disclosed, so analysts should obtain a live sample if operationally safe to confirm the phishing vector. Given the observed indicators—resolved IP, multiple vendor detections, blocklist inclusion, and PhishDestroy takedown—defenders should treat the domain as a high‑confidence phishing indicator. Recommended actions include adding the fully qualified domain name and its resolving IP address to outbound and inbound firewall deny lists, updating DNS‑based blocking feeds, and monitoring for any sudden changes in DNS resolution or additional hosting footprints.
Renseignements sur la sécurité réseau
Processus de réponse aux menaces Pipeline
Statut de la liste de blocage publique
Capture enregistrée
Informations sur les domaines
Détails techniquesDNS, SAN SSL, horodatages
Analyse VirusTotal
Données factuelles et rapports externes
Ce site vous a-t-il affecté ?
Si vous avez saisi des informations d'identification de compte, des informations personnelles ou de paiement, ou téléchargé un fichier à partir de ce domaine, agissez immédiatement. Vous trouverez ci-dessous des ressources pour vous aider à signaler l'incident et à vous protéger.
Signalez-le à vos autorités locales
Sélectionnez votre pays pour obtenir contacts officiels en matière de cybercriminalité ou créer un projet de plainte →.
Vérifier n'importe quel domaine
Analyse des menaces à l'aide de listes de blocage stockées, de WHOIS, de DNS et de preuves d'analyse publique
Scanner maintenantSignaler une tentative d'hameçonnage
Signalez les domaines suspects à notre base de données des menaces — protégez la communauté
SignalerFlux d'alertes en temps réel
Rapports de phishing récents et changements de disponibilité observés
SurveillerRestez informés, restez en sécurité
Surveillez les menaces en temps réel ou signalez cette alerte si vous pensez qu'il s'agit d'un faux positif