virtufinanciao[.]top
“Virtu Financial”
virtufinanciao.top — Contenu indisponible (HTTP 502). Usurpation de l'identité de la marque : Arbitrum; Type d'arnaque : Wallet/seed Phishing. Résumé des preuves: VirusTotal 3/95 (alphaMountain.ai, Chong Lua Dao, Gridinsoft); URLQuery 100 det.; URLScan malicious verdict; 1 external blocklist match (ScamSniffer); PhishDestroy score 100/100. Bureau d’enregistrement: Gname.
L’analyse détaillée de PhishDestroy AI reste en anglais afin de préserver le relevé forensique original.
This domain, virtufinanciao.top, is flagged for brand impersonation targeting the Arbitrum cryptocurrency platform. Analysis indicates the site presents itself as Virtu Financial, a legitimate trading entity, to deceive users into interacting with fraudulent financial services. The threat type aligns with credential harvesting and potential asset drainage, though no specific drainer kit signature has been confirmed in this instance. The domain's infrastructure and content suggest a targeted campaign against users familiar with Arbitrum's ecosystem, likely aiming to exploit trust in established financial brands to facilitate unauthorized transactions or data exfiltration. Infrastructure analysis reveals the domain resolves to the IP address 43.174.14.42 and was registered on October 25, 2025, through Gname.com Pte. Ltd. Detection metrics indicate a VirusTotal score of 3/95, with security vendors identifying malicious or suspicious behavior. The domain appears on two security blocklists and is actively blocked by monitoring systems such as ScamSniffer and PhishDestroy. The Gridinsoft trust score of 1/100 further corroborates the elevated risk level, reflecting minimal reputation and high likelihood of malicious intent. No association with Google Safe Browsing (GSB) alerts was recorded at the time of analysis, though this does not diminish the domain's verified malicious indicators. As of the latest assessment, virtufinanciao.top has been taken offline, likely in response to detection and reporting by security entities. However, the residual risk remains elevated due to the domain's recent registration and the persistent threat of similar campaigns emerging from the same registrar or IP range. Users who interacted with the site prior to its takedown are advised to monitor accounts for unauthorized activity, rotate credentials, and verify transaction histories. Organizations managing brand protection for Arbitrum or Virtu Financial should remain vigilant for domain squatting variations, particularly those leveraging similar naming conventions or registrars with historically low abuse mitigation.
Signaux de sécurité
Renseignements sur la sécurité réseau
Processus de réponse aux menaces Pipeline
Statut de la liste de blocage publique
Capture enregistrée
Informations sur les domaines
Détails techniquesDNS, SAN SSL, horodatages
ICANN OVERSIGHT
Contexte de l’accréditation et du RAA
Contexte de l’accréditation et du RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Analyse VirusTotal
Données factuelles et rapports externes
Ce site vous a-t-il affecté ?
Si vous avez saisi des informations d'identification de compte, des informations personnelles ou de paiement, ou téléchargé un fichier à partir de ce domaine, agissez immédiatement. Vous trouverez ci-dessous des ressources pour vous aider à signaler l'incident et à vous protéger.
Signalez-le à vos autorités locales
Sélectionnez votre pays pour obtenir contacts officiels en matière de cybercriminalité ou créer un projet de plainte →.
Vérifier n'importe quel domaine
Analyse des menaces à l'aide de listes de blocage stockées, de WHOIS, de DNS et de preuves d'analyse publique
Scanner maintenantSignaler une tentative d'hameçonnage
Signalez les domaines suspects à notre base de données des menaces — protégez la communauté
SignalerFlux d'alertes en temps réel
Rapports de phishing récents et changements de disponibilité observés
SurveillerRestez informés, restez en sécurité
Surveillez les menaces en temps réel ou signalez cette alerte si vous pensez qu'il s'agit d'un faux positif