recoveryassaetmgmt[.]icu
“Recovery Phrase”
recoveryassaetmgmt.icu — Contenu indisponible (HTTP 502). Usurpation de l'identité de la marque : Blockchain; Type d'arnaque : Crypto Scam. Résumé des preuves: VirusTotal 7/93 (alphaMountain.ai, BitDefender, CyRadar, Forcepoint ThreatSeeker, Fortinet); URLScan malicious verdict; PhishDestroy score 71/100.
L’analyse détaillée de PhishDestroy AI reste en anglais afin de préserver le relevé forensique original.
The domain recoveryassaetmgmt.icu was registered on February 21, 2026 and is currently listed as offline. Infrastructure analysis shows the hostname resolves to the IPv4 address 192.3.141.252, which is hosted in the United States under ASN 36352 owned by HostPapa. The site was identified by the PhishDestroy blocklist and appears on a single security blocklist, confirming its inclusion in known phishing mitigation feeds. VirusTotal scans report that 7 of 93 antivirus and URL‑reputation engines flag the domain as malicious, indicating partial but notable consensus among detection vendors.
The TLS certificate presented on the site is identified as version R11, and the page title returned by the HTTP response is "Recovery Phrase," matching the observed phishing kit label "Recovery Scam" and the broader classification of a crypto‑related scam. Gridinsoft assigns the domain a trust score of 0 out of 100, further evidencing its malicious reputation. No additional public threat‑intel sources such as OTX or Safe Browsing entries are referenced in the available data.
Because the site is offline, content cannot be verified, but the combination of registration date, hosting details, blocklist presence, vendor detections, and low trust score provides sufficient evidence to deem the domain a confirmed crypto phishing threat. Defenders should immediately block the domain and its resolved IP address at perimeter firewalls, DNS resolvers, and proxy filters. Ongoing monitoring of the 192.3.141.252 address for any re‑hosting activity is advised, as well as inclusion of the domain in internal threat‑intel feeds to prevent future user exposure.
Processus de réponse aux menaces Pipeline
Statut de la liste de blocage publique
Capture enregistrée
Informations sur les domaines
Détails techniquesDNS, SAN SSL, horodatages
ZONE SHORTDOT · PREUVES PUBLIQUES
.icu
ShortDot zone evidence
ShortDot zone evidence
The linked repository preserves daily zone observations across seven ShortDot-operated TLDs, including registration volume and abuse-related indicators. This registry context is supporting background and is not an independent detection for the domain in this report.
Analyse forensique
Analyse VirusTotal
Données factuelles et rapports externes
Ce site vous a-t-il affecté ?
Si vous avez saisi des informations d'identification de compte, des informations personnelles ou de paiement, ou téléchargé un fichier à partir de ce domaine, agissez immédiatement. Vous trouverez ci-dessous des ressources pour vous aider à signaler l'incident et à vous protéger.
Signalez-le à vos autorités locales
Sélectionnez votre pays pour obtenir contacts officiels en matière de cybercriminalité ou créer un projet de plainte →.
Vérifier n'importe quel domaine
Analyse des menaces à l'aide de listes de blocage stockées, de WHOIS, de DNS et de preuves d'analyse publique
Scanner maintenantSignaler une tentative d'hameçonnage
Signalez les domaines suspects à notre base de données des menaces — protégez la communauté
SignalerFlux d'alertes en temps réel
Rapports de phishing récents et changements de disponibilité observés
SurveillerRestez informés, restez en sécurité
Surveillez les menaces en temps réel ou signalez cette alerte si vous pensez qu'il s'agit d'un faux positif