midnight-site[.]onrender[.]com
Analyse phishing et sécurité de midnight-site.onrender.com
“Midnight TGE | Home”
midnight-site.onrender.com — Contenu indisponible (HTTP 404). Usurpation de l'identité de la marque : Across. Résumé des preuves: VirusTotal 10/95 (ChainPatrol, alphaMountain.ai, BitDefender, CRDF, CyRadar); PhishDestroy score 80/100. Bureau d’enregistrement: Render Services.
L’analyse détaillée de PhishDestroy AI reste en anglais afin de préserver le relevé forensique original.
Analysis indicates that midnight-site.onrender.com was provisioned on the Render hosting platform (ASN 397273) and resolves to IP 216.24.57.251, a server located in the United States. The site presented a HTTP 404 response at the time of investigation, and its SSL certificate was issued by Google Trust Services under the WE1 intermediate, confirming that TLS was correctly configured despite the error page. The page title returned by the server was “Midnight TGE | Home”, which does not reveal any legitimate brand and is consistent with a placeholder page often used in phishing infrastructure. VirusTotal recorded ten detections out of ninety‑five scanning engines, and the domain appears on a single external blocklist.
PhishDestroy has already taken the domain offline, and the current status is reported as “taken offline”. The hosting environment reported Cloudflare services and HTTP/3 support, suggesting that the attacker leveraged a CDN to obscure origin details. Registration was performed through Render Services Inc., and the domain’s nameserver information is missing (NS_NOT_FOUND). No additional intelligence such as Safe Browsing or OTX references was available, and the content of the site could not be captured because the server returned a 404 and the domain is now offline.
Consequently, the exact phishing payload, target brand, or credential‑harvesting mechanism remains unknown. Defenders should block the domain and its resolved IP address at perimeter and DNS layers, add the domain to internal threat‑intel feeds, and continue monitoring the ASN for any new sub‑domains that may be launched with similar techniques. Ongoing surveillance of Render‑hosted infrastructure is advised, as the provider has been used for prior malicious deployments.
Processus de réponse aux menaces Pipeline
Statut de la liste de blocage publique
Technologies · 2 identified
Cloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com Confiance à 100 %HTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org Confiance à 100 %Analyse VirusTotal
Preuves archivées
Données factuelles et rapports externes
Ce site vous a-t-il affecté ?
Si vous avez saisi des informations d'identification de compte, des informations personnelles ou de paiement, ou téléchargé un fichier à partir de ce domaine, agissez immédiatement. Vous trouverez ci-dessous des ressources pour vous aider à signaler l'incident et à vous protéger.
Signalez-le à vos autorités locales
Sélectionnez votre pays pour obtenir contacts officiels en matière de cybercriminalité ou créer un projet de plainte →.
Vérifier n'importe quel domaine
Analyse des menaces à l'aide de listes de blocage stockées, de WHOIS, de DNS et de preuves d'analyse publique
Scanner maintenantSignaler une tentative d'hameçonnage
Signalez les domaines suspects à notre base de données des menaces — protégez la communauté
SignalerFlux d'alertes en temps réel
Rapports de phishing récents et changements de disponibilité observés
SurveillerRestez informés, restez en sécurité
Surveillez les menaces en temps réel ou signalez cette alerte si vous pensez qu'il s'agit d'un faux positif