learn-dydx-trade[.]typedream[.]app
“404: This page could not be found.”
learn-dydx-trade.typedream.app — Contenu indisponible. Usurpation de l'identité de la marque : dYdX; Type d'arnaque : Crypto Scam. Résumé des preuves: VirusTotal 16/93 (ADMINUSLabs, ChainPatrol, alphaMountain.ai, BitDefender, CRDF); CF Radar malicious; PhishDestroy score 95/100. Bureau d’enregistrement: Squarespace Domains II.
L’analyse détaillée de PhishDestroy AI reste en anglais afin de préserver le relevé forensique original.
Analysis of learn-dydx-trade.typedream.app shows a newly registered domain created on 21 February 2026 that is currently offline and returns a 404 HTTP status. The site was hosted behind Cloudflare (ASN 13335) and resolves to the IP address 188.114.97.3 located in the United States. SSL termination is provided by Google Trust Services under the WE1 certificate, indicating the use of Google Cloud infrastructure. Fingerprinting of the web stack reveals Node.js, React, Next.js, Google Cloud Trace, Google Cloud CDN and Cloudflare Browser Insights, all typical of modern JavaScript‑heavy applications. Registration was performed through Squarespace Domains II LLC, a known registrar for many short‑lived abuse campaigns.
The domain is explicitly listed as impersonating the dYdX brand and is classified as a crypto‑related scam. VirusTotal has recorded detections from 16 of 93 scanning engines, and the domain appears on at least one external blocklist, namely PhishDestroy, which has already blocked it. No additional threat‑intel feeds such as OTX or Google Safe Browsing were referenced in the supplied data. Given the combination of brand impersonation, a recent creation date, active detections by multiple vendors, and a hosted infrastructure that can be rapidly provisioned, the domain should be treated as a confirmed malicious actor targeting users of the dYdX platform.
Defenders should add the domain to internal block lists, update DNS filtering rules to deny resolution, and monitor for any related C2 infrastructure that may share the same IP or Cloudflare configuration. Since the site currently returns a 404 page, any future change in HTTP response should be re‑examined promptly. Analysts should also watch for new domains registered by the same registrar that contain the “dydx” keyword, as the pattern suggests an automated naming scheme. Continuous correlation with threat‑intel feeds will help capture any resurgence of the campaign.
Renseignements sur la sécurité réseau
Processus de réponse aux menaces Pipeline
Statut de la liste de blocage publique
Technologies · 10 identified
Node.js is an open-source, cross-platform, JavaScript runtime environment that executes JavaScript code outside a web browser.
nodejs.org Confiance à 100 %React is an open-source JavaScript library for building user interfaces or UI components.
reactjs.org Confiance à 100 %Next.js is a React framework for developing single page Javascript applications.
nextjs.org Confiance à 100 %Google Cloud Trace is a distributed tracing system that collects latency data from applications and displays it in the Google Cloud Console.
cloud.google.com Confiance à 100 %Cloud CDN uses Google's global edge network to serve content closer to users.
cloud.google.com Confiance à 100 %Cloudflare Browser Insights is a tool that measures the performance of websites from the perspective of users.
www.cloudflare.com Confiance à 100 %Cloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com Confiance à 100 %HTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org Confiance à 100 %Analyse VirusTotal
Analyse de la configuration du site
Données factuelles et rapports externes
Ce site vous a-t-il affecté ?
Si vous avez saisi des informations d'identification de compte, des informations personnelles ou de paiement, ou téléchargé un fichier à partir de ce domaine, agissez immédiatement. Vous trouverez ci-dessous des ressources pour vous aider à signaler l'incident et à vous protéger.
Signalez-le à vos autorités locales
Sélectionnez votre pays pour obtenir contacts officiels en matière de cybercriminalité ou créer un projet de plainte →.
Vérifier n'importe quel domaine
Analyse des menaces à l'aide de listes de blocage stockées, de WHOIS, de DNS et de preuves d'analyse publique
Scanner maintenantSignaler une tentative d'hameçonnage
Signalez les domaines suspects à notre base de données des menaces — protégez la communauté
SignalerFlux d'alertes en temps réel
Rapports de phishing récents et changements de disponibilité observés
SurveillerRestez informés, restez en sécurité
Surveillez les menaces en temps réel ou signalez cette alerte si vous pensez qu'il s'agit d'un faux positif