vfna[.]cc
Analyse phishing et sécurité de vfna.cc
“AI-BMN 5.0”
vfna.cc — Contenu indisponible (HTTP 502). Type d'arnaque : Crypto Drainer. Résumé des preuves: VirusTotal 3/95 (alphaMountain.ai, Forcepoint ThreatSeeker, G-Data); 1 external blocklist match (ScamSniffer); PhishDestroy score 65/100. Bureau d’enregistrement: Gname.
L’analyse détaillée de PhishDestroy AI reste en anglais afin de préserver le relevé forensique original.
The domain vfna.cc was created on June 22, 2025 and is registered through Gname.com Pte. Ltd. Infrastructure analysis shows the domain resolves to IP address 104.21.85.66, which belongs to Cloudflare, Inc. (AS13335) and is located in the United States. The authoritative nameservers are gigi.ns.cloudflare.com and matt.ns.cloudflare.com, confirming that the site is fronted by Cloudflare’s edge network and is delivering content over HTTP/3. An SSL certificate issued by Google Trust Services under the WE1 label secures the connection, indicating a valid TLS handshake despite the malicious intent.
The page title returned by the server is "AI-BMN 5.0"; however, the site currently returns an HTTP 503 Service Unavailable status and has been taken offline, limiting direct content inspection. VirusTotal reports that three out of ninety‑five scanning engines have flagged the domain, providing independent confirmation of its malicious nature. The domain appears on two public blocklists and is specifically listed by PhishDestroy and ScamSniffer as a wallet/seed phishing campaign, aligning with the classified scam type of Wallet/Seed Phishing.
Gridinsoft assigns a trust score of 0 out of 100, further reinforcing the assessment of high risk. Defenders should continue to block the domain at network perimeter devices, update local and cloud‑based URL filtering lists, and monitor for any re‑hosting attempts that might arise from the same IP range or registrar. Because the site is offline, content‑level analysis is limited; investigators should rely on the observed infrastructure indicators, detection vendor signals, and blocklist listings to prioritize remediation and threat‑intel sharing.
Processus de réponse aux menaces Pipeline
Statut de la liste de blocage publique
Technologies · 2 identified
Cloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com Confiance à 100 %HTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org Confiance à 100 %Analyse VirusTotal
Preuves archivées
Données factuelles et rapports externes
Ce site vous a-t-il affecté ?
Si vous avez saisi des informations d'identification de compte, des informations personnelles ou de paiement, ou téléchargé un fichier à partir de ce domaine, agissez immédiatement. Vous trouverez ci-dessous des ressources pour vous aider à signaler l'incident et à vous protéger.
Signalez-le à vos autorités locales
Sélectionnez votre pays pour obtenir contacts officiels en matière de cybercriminalité ou créer un projet de plainte →.
Vérifier n'importe quel domaine
Analyse des menaces à l'aide de listes de blocage stockées, de WHOIS, de DNS et de preuves d'analyse publique
Scanner maintenantSignaler une tentative d'hameçonnage
Signalez les domaines suspects à notre base de données des menaces — protégez la communauté
SignalerFlux d'alertes en temps réel
Rapports de phishing récents et changements de disponibilité observés
SurveillerRestez informés, restez en sécurité
Surveillez les menaces en temps réel ou signalez cette alerte si vous pensez qu'il s'agit d'un faux positif