monsprotocol[.]io
Analyse phishing et sécurité de monsprotocol.io
“403 Forbidden”
monsprotocol.io — Contenu indisponible (HTTP 502). Usurpation de l'identité de la marque : Sei; Type d'arnaque : Brand Impersonation. Résumé des preuves: VirusTotal 1/93 (Emsisoft); 2 external blocklist matches (ScamSniffer, Enkrypt); PhishDestroy score 66/100.
L’analyse détaillée de PhishDestroy AI reste en anglais afin de préserver le relevé forensique original.
Evidence Analysis
Analysis of monsprotocol.io indicates the domain was created on 21 February 2026 and currently resolves to the IP address 188.114.96.3. The IP belongs to Cloudflare, Inc. (AS13335) and is geolocated in the United States. The site presents a TLS certificate labelled “WE1” and responds to HTTP requests with a 403 Forbidden page title, meaning no legitimate content is being served at the time of testing. The domain is explicitly classified as a brand‑impersonation campaign targeting the cryptocurrency platform Sei.
This classification is supported by three independent blocklists—PhishDestroy, ScamSniffer, and Enkrypt—that have listed the domain as offline, and by its appearance on three security blocklists overall. A Gridinsoft trust score of 0 / 100 further reflects a lack of trust. VirusTotal scanning shows a single detection out of ninety‑three security vendors, confirming that at least one vendor flagged the domain as malicious.
Although the 403 response prevents direct observation of a phishing landing page, the combination of recent registration, Cloudflare hosting, low trust rating, and multiple blocklist listings provides strong evidence that monsprotocol.io was used for brand‑impersonation. Defenders should treat the domain as a high‑confidence indicator of phishing activity: add it to URL filtering and web‑proxy blocklists, block the associated IP address 188.114.96.3 at the network perimeter, and monitor DNS logs for any future resolution attempts. Continuous observation is recommended to capture any changes in the TLS certificate, hosting provider, or registration status that could signal a re‑activation of the malicious campaign.
Couverture des données12 recorded checks
Processus de réponse aux menaces Pipeline
Statut de la liste de blocage publique
Analyse forensique
Analyse VirusTotal
Données factuelles et rapports externesIndependent lookups and source reports
“CultDrainer”
Victim safety and official reportingImmediate actions and verified reporting channels
Si vous avez saisi des informations d'identification de compte, des informations personnelles ou de paiement, ou téléchargé un fichier à partir de ce domaine, agissez immédiatement. Vous trouverez ci-dessous des ressources pour vous aider à signaler l'incident et à vous protéger.
Signalez-le à vos autorités locales
Sélectionnez votre pays pour obtenir contacts officiels en matière de cybercriminalité ou créer un projet de plainte →.