rnbw-coiniist[.]co
“Rainbow Token Sale - CoinList”
rnbw-coiniist.co — Contenu indisponible (HTTP 502). Usurpation de l'identité de la marque : Across; Type d'arnaque : Brand Impersonation. Résumé des preuves: VirusTotal 11/95 (ChainPatrol, alphaMountain.ai, CRDF, CyRadar, G-Data); URLScan malicious verdict; 1 external blocklist match (ScamSniffer); PhishDestroy score 83/100. Bureau d’enregistrement: Web Commerce Communica….
L’analyse détaillée de PhishDestroy AI reste en anglais afin de préserver le relevé forensique original.
This domain is flagged as an elevated-risk brand impersonation site designed to deceive users of the Across protocol. Analysis indicates the infrastructure was specifically crafted to mimic legitimate token sales, likely to facilitate unauthorized asset transfers or credential harvesting under the guise of a "Rainbow Token Sale - CoinList" campaign. The threat type is classified as crypto brand impersonation, with the potential to enable wallet-draining attacks or phishing for sensitive authentication details. Infrastructure analysis reveals the domain rnbw-coiniist.co was registered on December 10, 2025, through Web Commerce Communications Limited, a registrar frequently associated with high-risk domains. It resolves to the IP address 172.67.160.120, hosted on AS13335 (Cloudflare, Inc.), a network commonly leveraged to obscure malicious activity behind content delivery networks. The domain lacks an SSL certificate, further reducing its legitimacy. Security vendors on VirusTotal flagged the domain at a ratio of 11/95, while it appears on two blocklists (PhishDestroy and ScamSniffer), reinforcing its malicious classification. No historical trust scores or benign associations were identified during analysis. Mitigation steps for this threat type include immediate blacklisting of the domain and IP across all organizational security controls. Users who interacted with the site should revoke any wallet permissions granted during the session and monitor transaction histories for unauthorized activity. Network administrators are advised to implement DNS sinkholing for the domain and its associated IP to prevent further access. Given the domain's current offline status, continuous monitoring for re-emergence or similar impersonation attempts targeting Across or related DeFi platforms is recommended. Organizations should also educate users on verifying token sale legitimacy through official channels before engaging with any promotional campaigns.
Processus de réponse aux menaces Pipeline
Statut de la liste de blocage publique
Analyse VirusTotal
Données factuelles et rapports externes
Ce site vous a-t-il affecté ?
Si vous avez saisi des informations d'identification de compte, des informations personnelles ou de paiement, ou téléchargé un fichier à partir de ce domaine, agissez immédiatement. Vous trouverez ci-dessous des ressources pour vous aider à signaler l'incident et à vous protéger.
Signalez-le à vos autorités locales
Sélectionnez votre pays pour obtenir contacts officiels en matière de cybercriminalité ou créer un projet de plainte →.
Vérifier n'importe quel domaine
Analyse des menaces à l'aide de listes de blocage stockées, de WHOIS, de DNS et de preuves d'analyse publique
Scanner maintenantSignaler une tentative d'hameçonnage
Signalez les domaines suspects à notre base de données des menaces — protégez la communauté
SignalerFlux d'alertes en temps réel
Rapports de phishing récents et changements de disponibilité observés
SurveillerRestez informés, restez en sécurité
Surveillez les menaces en temps réel ou signalez cette alerte si vous pensez qu'il s'agit d'un faux positif