Aller au rapport de sécurité
Checked 09/08/2026 Ref 4C6A5F79

SUSPICIOUS — FLAGGED

venom-team[.]gitbook[.]io

Analysis of venom-team.gitbook.io indicates that the domain is actively hosting a crypto‑drainer phishing campaign.

68/100 evidence score · Flagged
VirusTotal
0/91
Blocklists
No stored match
Disponibilité
Dernier actif connu · HTTP 307
Report / Add Evidence Appeal this listing
2026-06-09 15:04 UTCDernier actif connu · HTTP 307

Do not enter credentials, seed phrases, payment details, or personal information on this domain.

⚠️
Suspicious Domain — Listed on PhishDestroy
Liste des menaces PhishDestroy stockée. VirusTotal analysis stored; no vendor detections were recorded at check time. Faites preuve d’une extrême prudence – ne saisissez pas d’informations d’identification ou d’informations personnelles.
Jump to section
Résumé du rapport

venom-team.gitbook.io — Dernier actif connu (HTTP 307). Type d'arnaque : Crypto Drainer. Résumé des preuves: VirusTotal 0/91; PhishDestroy score 68/100. Bureau d’enregistrement: GitBook.

L’analyse détaillée de PhishDestroy AI reste en anglais afin de préserver le relevé forensique original.

Evidence Analysis

Ref 4C6A5F79

Analysis of venom-team.gitbook.io indicates that the domain is actively hosting a crypto‑drainer phishing campaign. The site presents the title "VENOM MULTI QR | VENOM TEAM Docs" and resolves to the IP address 172.64.147.209, which is owned by Cloudflare, Inc. The domain was registered through the GitBook service and carries an SSL certificate issued by Google Trust Services under the WE1 authority. HTTP traffic returns a 307 redirect, and the infrastructure leverages GitBook, Google Cloud, Cloudflare, HSTS, Google Cloud Trace, and HTTP/3. The page is listed on a single security blocklist and has been blocked by PhishDestroy. The Gridinsoft trust score is 0 / 100, reflecting a high risk assessment. VirusTotal records show that 91 scanning engines have examined the domain without reporting detections, though the absence of flags does not imply benign intent. Current classification places the domain under investigation with an active status. Defenders should treat the domain as malicious, block connections to the associated IP, and incorporate the domain into URL filtering and sink‑hole feeds. Monitoring for any changes in DNS resolution, additional blocklist listings, or new scanner detections is recommended to maintain situational awareness.

VirusTotal
VirusTotal
0 det.
Certificat TLS
Google Trust Services
Statut observé
Dernier actif connu 307
PhishDestroy
DestroyList
Répertorié
Couverture des données12 recorded checks
VirusTotal checked — no detections recorded URLQuery pas vérifié PhishStats pas vérifié OTX no community references CF Radar scan completed URLScan capture not submitted URLScan verdict verdict indisponible Blocs DNS 14 vérifié — aucun blocage TLS valid certificate, 52d WHOIS not parsed Capture d'écran 2 captures · 2 sources Chaîne de redirection non sondé

Processus de réponse aux menaces Pipeline

Découverte
Checks
Reports
Disponibilité
7/9

Statut de la liste de blocage publique

Capture enregistrée

Informations sur les domaines

Domaine
Serveur / ASN cloudflare · AS13335 Cloudflare, Inc.
IP Context Cloudflare shared edge origin IP hidden La réputation Edge-IP n’est pas attribuée à ce domaine.
Registrar (base domain) GitBook
Adresse IP 172.64.147.209 CDN
LocalisationCA Toronto, CA
RéseauAS13335 · Cloudflare, Inc.
L'adresse IP d'origine est cachée derrière un proxy CDN. Les résultats d’IP inversé pour l’adresse périphérique contiennent des locataires non liés ; trouver l’origine nécessite un DNS passif ou des données de transparence des certificats.
Statut HTTP307 Temporary Redirect
Elapsed Since First Report 8 days
Ce que nous comptons Raw elapsed time since the first stored abuse report. It is not a registrar response-time measurement. Latest observed status: Dernier actif connu.
Ce que contient chaque rapport Les enregistrements de rapports sortants stockés peuvent faire référence à des preuves disponibles à ce moment-là, telles que les verdicts des fournisseurs, les données d'enregistrement, les détails d'hébergement, les classifications ou les captures d'écran. Cette page ne déduit pas la charge utile exacte livrée, la réception, l'accusé de réception ou l'action d'un destinataire.
Détails techniquesDNS, SAN SSL, horodatages
Première détection09/06/2026
Submitted URLhttps://venom-team.gitbook.io/venom-team-docs/documentation
TLS Fingerprint
TLS Observationvalid from 19/05/2026scanned 13/06/2026
TLS SAN Domainsgitbook.io
Favicon Hash
Titre de la page
VENOM MULTI QR | VENOM TEAM Docs
Certificat TLS
Valid transport encryption · Émis par Google Trust Services · valid for 52 days
Technologies · 6 identified
GitBook
Documentation

GitBook is a command-line tool for creating documentation using Git and Markdown.

www.gitbook.com Confiance à 100 %
Google Cloud
IaaS

Google Cloud is a suite of cloud computing services.

cloud.google.com Confiance à 100 %
HSTS
Sécurité

HTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.

www.rfc-editor.org Confiance à 100 %
Google Cloud Trace
Performance

Google Cloud Trace is a distributed tracing system that collects latency data from applications and displays it in the Google Cloud Console.

cloud.google.com Confiance à 100 %
Cloudflare
CDN

Cloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.

www.cloudflare.com Confiance à 100 %
HTTP/3
Miscellaneous

HTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.

httpwg.org Confiance à 100 %
Detected via Cloudflare Radar · Wappalyzer engine
Signaler ce domaine Envoyez des éléments de preuve et contribuez à protéger les autres

Analyse VirusTotal

0 / Les fournisseurs de sécurité 91 ont signalé ce domaine
View on VT
Last analyzed Previous stored snapshot: 0 detections
No VirusTotal engine marked the domain malicious in the stored analysis.
Analyse des performances du site

Google PageSpeed Insights — mobile performance audit of venom-team.gitbook.io · checked Jun 26, 2026

61
Needs Work
Performance
FCP
3.04s
First Contentful Paint
LCP
8.35s
Largest Contentful Paint
CLS
0.007
Cumulative Layout Shift
TBT
258ms
Total Blocking Time
SI
5.23s
Speed Index
Powered by Google PageSpeed Insights · Mobile strategy · Scores: 90-100 Good 50-89 Needs Work 0-49 Poor
Données factuelles et rapports externesIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
If credentials were compromised, report immediately. Do not engage with recovery scammers.

Si vous avez saisi des informations d'identification de compte, des informations personnelles ou de paiement, ou téléchargé un fichier à partir de ce domaine, agissez immédiatement. Vous trouverez ci-dessous des ressources pour vous aider à signaler l'incident et à vous protéger.

Europol
Trouvez le canal de signalement officiel pour votre pays de l'UE
National police directory
Méfiez-vous des escrocs qui prétendent vous aider à récupérer vos biens ! Les criminels peuvent recontacter leurs victimes tout en se faisant passer pour des enquêteurs, des avocats ou des agents de recouvrement. Ne payez pas de frais initiaux et ne partagez pas vos informations d'identification. En savoir plus sur la fraude liée aux aides à la reprise →

Signalez-le à vos autorités locales

Sélectionnez votre pays pour obtenir contacts officiels en matière de cybercriminalité ou créer un projet de plainte →.

Annuaire de 97 pays
Brouillon assisté par l'IA : les détails de l'incident sont traités par le fournisseur d'IA Examinez-le et soumettez-le vous-même
Intégrer ce rapportRead-only HTML widget
HTML · IFRAME

Intégrer ce rapport

Partagez ces informations sur les menaces sur votre site web ou votre blog

embed.html
<iframe
  src="https://phishdestroy.io/fr/embed/domain/venom-team.gitbook.io"
  title="PhishDestroy threat report for venom-team.gitbook.io"
  width="100%" height="320"
  loading="lazy"
  referrerpolicy="no-referrer"
  sandbox="allow-same-origin allow-popups allow-popups-to-escape-sandbox"
  style="border:0;border-radius:12px;max-width:100%"
></iframe>