safepalassets[.]com
“SafePal Wallet — Secure Crypto Wallet”
Résumé des preuves
This report analyzes the domain safepalassets.com, which impersonated the Binance brand and was categorized as a cryptocurrency scam. The site presented itself as the "SafePal Wallet — Secure Crypto Wallet," posing a threat to users by potentially collecting sensitive wallet credentials or funds through a fraudulent brand impersonation scheme.
Technical analysis reveals the domain was detected as malicious by 4 out of 95 VirusTotal vendors, with flags from ADMINUSLabs, Fortinet, Gridinsoft, and Seclookup. It appeared on 3 blocklists. The domain was registered through NiceNIC International Group Co., Limited and created on February 21, 2026. It resolved to IP address 104.21.83.5, located in the United States and hosted by AS13335 Cloudflare, Inc. The site lacked SSL encryption and used nameservers kay.ns.cloudflare.com and vick.ns.cloudflare.com.
The domain is currently offline and down, with a DOM risk score of 65, indicating a moderate to high risk level. Although inactive, the domain remains a potential threat if reactivated, and users should avoid any interaction with it or similar impersonation domains.
Instantané des preuves transmises
- Envoyé
- Entrées du registre
- 1
- ID du dossier
PD-20260216-2AEE0A- Titre de la page capturée
- SafePal Wallet — Secure Crypto Wallet
- Artefact PDF
- Preuve PDF
Texte intégral des preuves
Policy Violations: “Services may be used only for lawful purposes… fraud, abuse and illegal activity prohibited. Violations may result in immediate suspension.” + dedicated abuse handling and takedown
Applicable Laws: Crimes Ordinance Cap.200 (Fraud), Theft Ordinance Cap.210 §16A (fraud by deception), Personal Data (Privacy) Ordinance Cap.486
Data Coverage
Renseignements sur la sécurité réseau
Processus de réponse aux menaces Pipeline
Couverture des listes de blocage
10 sources externes surveillées · instantané du 13/08/2026
8 sources externes surveillées Aucune correspondance
Preuves du résultat enregistrées
Résultat et attribution du retrait
- Résultat
held- Disponibilité
unreachable- Cause
registrar_client_hold- Acteur
- NICENIC INTERNATIONAL GROUP CO., LIMITED
- Mécanisme
client_hold- Confiance
- 95%
- Première observation
- Dernière observation
Indisponibilité estimée
Délai avant indisponibilité: 0 hSHA-256 de la preuve 622fc66c78e7
Chronologie de détection
-
Cloudflare Radar
Analyse Cloudflare Radar enregistrée · Ouvrir l’analyse
-
Cloudflare Radar
Analyse Cloudflare Radar enregistrée · Ouvrir l’analyse
-
Disponibilité
Première valeur enregistrée : DNS inactif
f93a11f87e4d -
Disponibilité
DNS inactif → Inconnu
08d5b76c817c -
Disponibilité
Inconnu → DNS inactif
9fb281290fa6 -
Disponibilité
DNS inactif → Retenu
4c1f35901ea7 -
Disponibilité
Retenu → DNS inactif
f52d526b76a1 -
Disponibilité
DNS inactif → Inconnu
c20051f24aa8 -
Disponibilité
Inconnu → Retenu
bfc7f34cf3c9 -
Disponibilité
Retenu → Inconnu
6dea56ad79ea
Tout afficher (14)
-
Disponibilité
Inconnu → DNS inactif
6dfe9145995c -
Disponibilité
DNS inactif → Retenu
8753645797e6 -
Disponibilité
Retenu → DNS inactif
641ed81dc4d5 -
Disponibilité
DNS inactif → Inconnu
9fee19976ac2 -
Disponibilité
Inconnu → Retenu
8e8b259aec86 -
Disponibilité
Retenu → Inconnu
324c8fca970e -
Disponibilité
Inconnu → DNS inactif
d0b7046e8c2f -
Disponibilité
DNS inactif → Retenu
7489c7fdfc3d -
Disponibilité
Retenu → DNS inactif
ca9ed662b468 -
Disponibilité
DNS inactif → Inconnu
25d03123f464 -
Disponibilité
Inconnu → Retenu
a884f24bc6fa -
Disponibilité
Retenu → DNS inactif
92f667ff6e00 -
Disponibilité
DNS inactif → Inconnu
4a70999a7edd -
Disponibilité
Inconnu → Retenu
622fc66c78e7
Signalements communautaires
Signalé par 1 membre de la communauté ; première observation le 16/02/2026
- Signalements enregistrés
- 1
- URL signalées uniques
- 1
Renseignement communautaire
1 signalement communautaire
CatégoriePHISHING
Detection Summary The Anti-Phishing Volunteers & Associates Security Incident Response System has flagged this as a domain threat, classified as phishing attack against SafePal. Threat detected at 2026-02-19T19:09:27.182Z.
Capture enregistrée
Informations sur les domaines
Détails techniquesDNS, noms TLS et horodatages
ICANN OVERSIGHT
Contexte de l’accréditation et du RAA
Contexte de l’accréditation et du RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Analyse VirusTotal
Domaines ressemblants
187 domaines ressemblants enregistrés
Tout afficher (88)
100 affichés sur 187
Ce site vous a-t-il affecté ?
Si vous avez saisi des informations d'identification de compte, des informations personnelles ou de paiement, ou téléchargé un fichier à partir de ce domaine, agissez immédiatement. Vous trouverez ci-dessous des ressources pour vous aider à signaler l'incident et à vous protéger.
Signalez-le à vos autorités locales
Sélectionnez votre pays pour obtenir contacts officiels en matière de cybercriminalité ou créer un projet de plainte →.
Vérifier n'importe quel domaine
Analyse des menaces à l'aide de listes de blocage stockées, de WHOIS, de DNS et de preuves d'analyse publique
Scanner maintenantSignaler une tentative d'hameçonnage
Signalez les domaines suspects à notre base de données des menaces — protégez la communauté
SignalerFlux d'alertes en temps réel
Rapports de phishing récents et changements de disponibilité observés
SurveillerRestez informés, restez en sécurité
Surveillez les menaces en temps réel ou signalez cette alerte si vous pensez qu'il s'agit d'un faux positif