refixupdatenode[.]co
“Home | Dapps Leading Synthetic Protocol”
Résumé des preuves
The domain refixupdatenode.co was registered on 28 October 2025 through Global Domain Group LLC and is currently hosted by HostPapa (ASN 36352) in the United States, resolving to IP 198.23.156.130. The authoritative nameservers are ns1.host-forest.com and ns2.host-forest.com, and the MX record points to webmail.refixupdatenode.co. No TLS certificate is presented; HTTP requests return a 403 status, and the site has been taken offline at the time of analysis. The page title observed during earlier scans reads “Home | Dapps Leading Synthetic Protocol”, which is unrelated to the targeted brand but matches the pattern of a fabricated crypto‑related interface. The domain is classified as a wallet/seed phishing operation that leverages the Wallet Connect abuse kit to harvest private keys and recovery phrases.
It impersonates the decentralized exchange aggregator 1inch, a known high‑value target for credential theft. Detection infrastructure shows that the domain is listed on five security blocklists and has been flagged by multiple threat‑intelligence vendors, including PhishDestroy, ScamSniffer, Polkadot, Enkrypt, and Codeesura. VirusTotal analysis recorded 14 positive detections out of 95 scanners, and Gridinsoft assigned a trust score of 0 / 100, indicating a high confidence of malicious intent. The presence of a custom MX record and the lack of SSL suggest the operators prepared a functional mail system for exfiltrated data.
While the site is presently offline, the underlying infrastructure – shared hosting on HostPapa and the same IP address – may be reused for future campaigns. Defenders should add refixupdatenode.co to domain blocklists, monitor DNS queries for the associated IP and nameservers, and enforce strict validation of Wallet Connect URLs in client applications. Users of the 1inch platform should be reminded to verify the authenticity of any wallet‑connect prompts and to never disclose seed phrases to unsolicited services.
Data Coverage
Processus de réponse aux menaces Pipeline
Couverture des listes de blocage
10 sources externes surveillées · instantané du 12/08/2026
6 sources externes surveillées Aucune correspondance
Chronologie de détection
-
Cloudflare Radar
Analyse Cloudflare Radar enregistrée · Ouvrir l’analyse
Analyse VirusTotal
Ce site vous a-t-il affecté ?
Si vous avez saisi des informations d'identification de compte, des informations personnelles ou de paiement, ou téléchargé un fichier à partir de ce domaine, agissez immédiatement. Vous trouverez ci-dessous des ressources pour vous aider à signaler l'incident et à vous protéger.
Signalez-le à vos autorités locales
Sélectionnez votre pays pour obtenir contacts officiels en matière de cybercriminalité ou créer un projet de plainte →.
Vérifier n'importe quel domaine
Analyse des menaces à l'aide de listes de blocage stockées, de WHOIS, de DNS et de preuves d'analyse publique
Scanner maintenantSignaler une tentative d'hameçonnage
Signalez les domaines suspects à notre base de données des menaces — protégez la communauté
SignalerFlux d'alertes en temps réel
Rapports de phishing récents et changements de disponibilité observés
SurveillerRestez informés, restez en sécurité
Surveillez les menaces en temps réel ou signalez cette alerte si vous pensez qu'il s'agit d'un faux positif