automaticnoderefix[.]co
“Home | Dapps Leading Synthetic Protocol”
साक्ष्य सारांश
Analysis of automaticnoderefix.co, created on November 03, 2025 and currently taken offline, shows a high‑risk wallet/seed phishing operation targeting users of the 1inch platform. The site served a page titled "Home | Dapps Leading Synthetic Protocol" and was built with the Wallet Connect Abuse kit, a known vector for extracting private keys and seed phrases. The domain resolves to IP address 198.23.156.130, which is hosted in the United States under ASN 36352 owned by HostPapa.
Nameserver records point to ns1.host-forest.com and ns2.host-forest.com, and registration was performed through Global Domain Group LLC. No TLS certificate was in place, leaving the site accessible only via plain HTTP. Reputation metrics are extremely low: Scamadviser assigns a trust score of 1 / 100 and Gridinsoft a score of 0 / 100. The domain appears on five security blocklists—PhishDestroy, ScamSniffer, Polkadot, Enkrypt, and Codeesura—and VirusTotal reports 14 of 95 scanning engines flagging it as malicious.
These indicators collectively confirm the infrastructure’s malicious intent. While the site is no longer reachable, defenders should continue to block the domain and its hosting IP, monitor for any re‑registration attempts, and educate 1inch users about unsolicited wallet‑connect requests. Ongoing vigilance is recommended, especially given the low trust scores and the presence of the Wallet Connect Abuse kit, which is frequently repurposed for credential harvesting.
Data Coverage
सुरक्षा संकेत
धमकी प्रतिक्रिया पाइपलाइन
ब्लॉकलिस्ट कवरेज
10 निगरानी वाले बाहरी स्रोत · संग्रहीत स्नैपशॉट 11/08/2026
6 निगरानी वाले बाहरी स्रोत कोई मिलान नहीं
पहचान समयरेखा
-
Cloudflare Radar
Cloudflare Radar स्कैन संग्रहीत · स्कैन खोलें
वायरसटोटल विश्लेषण
क्या आप इस साइट से प्रभावित हुए?
यदि आपने खाता क्रेडेंशियल, व्यक्तिगत या भुगतान जानकारी दर्ज की है, या इस डोमेन से कोई फ़ाइल डाउनलोड की है, तो तुरंत कार्रवाई करें। घटना की रिपोर्ट करने और अपनी सुरक्षा करने में आपकी सहायता के लिए नीचे संसाधन दिए गए हैं।
अपने स्थानीय अधिकारियों को रिपोर्ट करें
आधिकारिक साइबर अपराध संपर्क, या एक शिकायत ड्राफ्ट बनाएं → प्राप्त करने के लिए अपना देश चुनें।
किसी भी डोमेन की जाँच करें
संग्रहीत ब्लॉकलिस्ट, WHOIS, DNS और सार्वजनिक स्कैन साक्ष्य का उपयोग करके खतरे का विश्लेषण
अभी स्कैन करेंफ़िशिंग की रिपोर्ट करें
संदिग्ध डोमेन हमारे थ्रेट डेटाबेस में जमा करें — समुदाय की सुरक्षा करें
रिपोर्ट करेंसीधा खतरा फीड
हाल की फ़िशिंग रिपोर्टें और उपलब्धता में परिवर्तन देखे गए
निगरानी करेंजानकारी में रहें, सुरक्षित रहें
लाइव खतरों की निगरानी करें या यदि आपको लगता है कि यह एक गलत सकारात्मक है तो इस लिस्टिंग को चुनौती दें।