MALICIOUS — CRITICAL
rvelix[.]com
The domain rvelix.com is confirmed to be a generic phishing site, with no specific brand impersonation or crypto drainer kit identified in the current analysis.
- VirusTotal
- 19/91
- Blocklists
- 2 · MetaMask, SEAL
- Disponibilité
- Accessible · accès restreint · HTTP 403
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
rvelix.com — Accessible · accès restreint (HTTP 403). Résumé des preuves: VirusTotal 19/91 (ADMINUSLabs, ChainPatrol, alphaMountain.ai, BitDefender, CRDF); 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 100/100. Bureau d’enregistrement: NameSilo.
L’analyse détaillée de PhishDestroy AI reste en anglais afin de préserver le relevé forensique original.
Evidence Analysis
The domain rvelix.com is confirmed to be a generic phishing site, with no specific brand impersonation or crypto drainer kit identified in the current analysis. The threat posed by this domain is classified as high, indicating a significant risk to users who may visit the site or interact with its content. The domain is designed to deceive users by mimicking legitimate websites, often to steal credentials or personal information.
Infrastructure analysis reveals that rvelix.com resolves to the IP address 188.114.97.3, which is located in California, USA, and is associated with CloudFlare, Inc. The domain was created on May 18, 2026, and is secured with an SSL certificate from Let's Encrypt. According to VirusTotal, 10 out of 95 security vendors have flagged this domain as malicious. The domain is registered through NameSilo, LLC, and currently appears on 3 security blocklists. It has been identified and blocked by PhishDestroy, MetaMask, and SEAL, indicating a coordinated effort to mitigate the threat.
The domain rvelix.com is currently offline, which suggests that it has been taken down by the registrar, hosting provider, or as a result of security actions. Despite the domain being offline, the risk remains as the site could be reactivated or the actors behind the campaign could use similar infrastructure. Users are advised to avoid visiting this domain and to report any related suspicious activity to their security teams. Organizations should consider adding this domain to their internal blocklists and monitor for any further indicators of compromise.
Couverture des données12 recorded checks
Renseignements sur la sécurité réseau Registrar context
Processus de réponse aux menaces Pipeline
Statut de la liste de blocage publique
Informations sur les domaines
Détails techniquesDNS, SAN SSL, horodatages
ICANN OVERSIGHT
Contexte de l’accréditation et du RAA
Contexte de l’accréditation et du RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Analyse VirusTotal
Données factuelles et rapports externesIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
Si vous avez saisi des informations d'identification de compte, des informations personnelles ou de paiement, ou téléchargé un fichier à partir de ce domaine, agissez immédiatement. Vous trouverez ci-dessous des ressources pour vous aider à signaler l'incident et à vous protéger.
Signalez-le à vos autorités locales
Sélectionnez votre pays pour obtenir contacts officiels en matière de cybercriminalité ou créer un projet de plainte →.