amazon-coin[.]com
“Claim Your Share of the Arbitrum Ecosystem | Up to $25,000 for Active Wallets”
On July 24, 2026 the domain amazon-coin.com was observed hosting a fake airdrop campaign that promised up to $25,000 for active wallets in the Arbitrum ecosystem. The site is currently offline, but historical records show that the domain resolved to the IP address 45.9.148.51, which is assigned to Nice IT Services Group Inc. in the Netherlands (AS49447). The domain was created on 21 February 2026 and was registered via Unstoppable Domains Inc., a registrar commonly used for cryptocurrency‑related domains. The TLS certificate presented on the site was identified as an R11‑grade certificate, indicating a low level of validation.
Reputation services rated the domain poorly: Gridinsoft gave it a score of 0/100, Scamadviser assigned 6/100, and the domain appears on a single security blocklist. VirusTotal analysis recorded detections from 2 of 93 antivirus engines, confirming malicious content despite the low detection count. The page title captured during the crawl—“Claim Your Share of the Arbitrum Ecosystem | Up to $25,000 for Active Wallets”—matches the typical language used in fraudulent airdrop schemes that lure cryptocurrency users with promises of large payouts. The campaign was flagged and taken down by the PhishDestroy blocklist, which now lists the domain as offline.
Evidence does not clarify the exact phishing kit or the full set of URLs that were served, and no screenshots or content snapshots are available. However, the combination of a freshly registered cryptocurrency‑related domain, a low‑trust SSL certificate, poor reputation scores, and the presence of a fake‑airdrop claim strongly suggests a financially motivated fraud operation targeting users of the Arbitrum network. Defenders should add 45.9.148.51 to network‑level deny lists, monitor for any resurrection of the domain or similar “amazon‑coin” patterns, and ensure that endpoint protection solutions are updated with the two VirusTotal detections.
धमकी प्रतिक्रिया पाइपलाइन
ब्लॉकलिस्ट कवरेज
10 निगरानी वाले बाहरी स्रोत · संग्रहीत स्नैपशॉट 10/08/2026
सहेजा गया कैप्चर
डोमेन इंटेलिजेंस
तकनीकी विवरणDNS, TLS नाम और समय-मुद्राएँ
ICANN OVERSIGHT
प्रत्यायन और आरएए संदर्भ
प्रत्यायन और आरएए संदर्भ
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
फॉरेंसिक इंटेलिजेंस
वायरसटोटल विश्लेषण
क्या आप इस साइट से प्रभावित हुए?
यदि आपने खाता क्रेडेंशियल, व्यक्तिगत या भुगतान जानकारी दर्ज की है, या इस डोमेन से कोई फ़ाइल डाउनलोड की है, तो तुरंत कार्रवाई करें। घटना की रिपोर्ट करने और अपनी सुरक्षा करने में आपकी सहायता के लिए नीचे संसाधन दिए गए हैं।
अपने स्थानीय अधिकारियों को रिपोर्ट करें
आधिकारिक साइबर अपराध संपर्क, या एक शिकायत ड्राफ्ट बनाएं → प्राप्त करने के लिए अपना देश चुनें।
किसी भी डोमेन की जाँच करें
संग्रहीत ब्लॉकलिस्ट, WHOIS, DNS और सार्वजनिक स्कैन साक्ष्य का उपयोग करके खतरे का विश्लेषण
अभी स्कैन करेंफ़िशिंग की रिपोर्ट करें
संदिग्ध डोमेन हमारे थ्रेट डेटाबेस में जमा करें — समुदाय की सुरक्षा करें
रिपोर्ट करेंसीधा खतरा फीड
हाल की फ़िशिंग रिपोर्टें और उपलब्धता में परिवर्तन देखे गए
निगरानी करेंजानकारी में रहें, सुरक्षित रहें
लाइव खतरों की निगरानी करें या यदि आपको लगता है कि यह एक गलत सकारात्मक है तो इस लिस्टिंग को चुनौती दें।