generaldiagnosticrefix[.]co
“Home | Dapps Leading Synthetic Protocol”
Résumé des preuves
The domain generaldiagnosticrefix.co was first observed on October 17 2025, registered via Global Domain Group LLC. It resolves to the IPv4 address 198.23.156.130, which is allocated to AS36352 (HostPapa) and geolocated to the United States. The authoritative nameservers are ns1.host-forest.com and ns2.host-forest.com. No TLS certificate is presented; HTTP requests return no SSL handshake, indicating the site operated over plain HTTP before being taken offline. The only visible page title returned by the web server is “Home | Dapps Leading Synthetic Protocol”, a generic phrase that does not reference the targeted brand.
Nevertheless, threat intelligence links the domain to a wallet/seed phishing campaign that impersonates the decentralized exchange aggregator 1inch. VirusTotal analysis recorded 13 positive detections out of 95 submitted scanners, corroborating malicious intent. The domain is listed on five public blocklists—PhishDestroy, ScamSniffer, Polkadot, Enkrypt, and Codeesura—each of which classifies it as a phishing or scam host. Gridinsoft assigns a trust score of 0 / 100, confirming the extreme risk rating.
The site’s current HTTP status is “offline”, suggesting that the hosting provider or a takedown request has removed the content. Despite the offline state, the infrastructure components—namely the hosting ASN, IP address, and nameserver configuration—remain active and could be reused for future campaigns. Defenders should continue to block the resolved IP and associated host‑forest nameservers at the network perimeter, add the domain to internal blocklists, and monitor for any re‑registration of the same name or reuse of the same hosting resources. Threat‑intel feeds should be updated to reflect the domain’s historical activity and its association with 1inch impersonation, enabling rapid correlation with similar future indicators.
Data Coverage
Processus de réponse aux menaces Pipeline
Couverture des listes de blocage
10 sources externes surveillées · instantané du 11/08/2026
6 sources externes surveillées Aucune correspondance
Chronologie de détection
-
Cloudflare Radar
Analyse Cloudflare Radar enregistrée · Ouvrir l’analyse
Analyse VirusTotal
Ce site vous a-t-il affecté ?
Si vous avez saisi des informations d'identification de compte, des informations personnelles ou de paiement, ou téléchargé un fichier à partir de ce domaine, agissez immédiatement. Vous trouverez ci-dessous des ressources pour vous aider à signaler l'incident et à vous protéger.
Signalez-le à vos autorités locales
Sélectionnez votre pays pour obtenir contacts officiels en matière de cybercriminalité ou créer un projet de plainte →.
Vérifier n'importe quel domaine
Analyse des menaces à l'aide de listes de blocage stockées, de WHOIS, de DNS et de preuves d'analyse publique
Scanner maintenantSignaler une tentative d'hameçonnage
Signalez les domaines suspects à notre base de données des menaces — protégez la communauté
SignalerFlux d'alertes en temps réel
Rapports de phishing récents et changements de disponibilité observés
SurveillerRestez informés, restez en sécurité
Surveillez les menaces en temps réel ou signalez cette alerte si vous pensez qu'il s'agit d'un faux positif