raydiunn[.]co[.]com
“Swap Raydium - Liquidity - Connect Wallet”
raydiunn.co.com — Non vérifié. Usurpation de l'identité de la marque : Across; Type d'arnaque : Wallet/seed Phishing. Résumé des preuves: VirusTotal 13/91 (ADMINUSLabs, alphaMountain.ai, BitDefender, Chong Lua Dao, ESET); Spamhaus DBL_PHISH; PhishDestroy score 89/100. Bureau d’enregistrement: Cloudflare.
L’analyse détaillée de PhishDestroy AI reste en anglais afin de préserver le relevé forensique original.
This domain is flagged as a brand impersonation threat with an elevated risk level, specifically targeting users of the Across cross-chain bridge protocol. The site presents itself as a legitimate wallet connection portal for Raydium liquidity swaps, a common tactic to deceive cryptocurrency users into exposing private keys or seed phrases during the connection process. Analysis indicates the domain raydiunn.co.com is currently offline but was previously active with notable malicious indicators. It resolves to IP address 104.21.94.254, hosted on Cloudflare infrastructure (AS13335). The domain lacks an SSL certificate, increasing the likelihood of interception during credential transmission. VirusTotal detection shows 15 out of 95 security vendors flagging this domain as malicious. It appears on two security blocklists, including PhishDestroy and PhishingDB, and was registered through Cloudflare, Inc. The page title found during analysis reads 'Swap Raydium - Liquidity - Connect Wallet,' directly referencing cryptocurrency operations to lend credibility to the fraudulent site. Mitigation against this type of brand impersonation threat requires heightened user awareness and technical safeguards. Users should verify domain authenticity by cross-referencing official project documentation before connecting wallets. Browser-based security extensions that block known phishing domains should be employed, and wallet software should be configured to reject connections from untrusted sources. Organizations managing cryptocurrency infrastructure should monitor for domains using similar naming patterns or impersonating their brand, particularly those hosted on content delivery networks that obscure origin servers. Network-level blocking of the resolved IP address (104.21.94.254) and domains with the 'ca82b1' seed pattern can prevent access to this and related malicious infrastructure.
Processus de réponse aux menaces Pipeline
Statut de la liste de blocage publique
Analyse forensique
Analyse VirusTotal
Preuves archivées
Données factuelles et rapports externes
Ce site vous a-t-il affecté ?
Si vous avez saisi des informations d'identification de compte, des informations personnelles ou de paiement, ou téléchargé un fichier à partir de ce domaine, agissez immédiatement. Vous trouverez ci-dessous des ressources pour vous aider à signaler l'incident et à vous protéger.
Signalez-le à vos autorités locales
Sélectionnez votre pays pour obtenir contacts officiels en matière de cybercriminalité ou créer un projet de plainte →.
Vérifier n'importe quel domaine
Analyse des menaces à l'aide de listes de blocage stockées, de WHOIS, de DNS et de preuves d'analyse publique
Scanner maintenantSignaler une tentative d'hameçonnage
Signalez les domaines suspects à notre base de données des menaces — protégez la communauté
SignalerFlux d'alertes en temps réel
Rapports de phishing récents et changements de disponibilité observés
SurveillerRestez informés, restez en sécurité
Surveillez les menaces en temps réel ou signalez cette alerte si vous pensez qu'il s'agit d'un faux positif