defillaio[.]com
“Defillama: DeFi TVL, Yields, Protocols and Chain Data”
साक्ष्य सारांश
This domain, defillaio.com, operates as a crypto drainer targeting users of the legitimate DeFi analytics platform DefiLlama. Analysis indicates the site mimics DefiLlama’s branding, including an identical page title, "Defillama: DeFi TVL, Yields, Protocols and Chain Data," to deceive victims into connecting wallets. The threat actor likely employed a drainer kit designed to siphon cryptocurrency assets upon interaction, a common tactic in DeFi-related fraud schemes. No specific drainer kit variant has been attributed to this domain at this time, but the impersonation pattern aligns with known crypto drainer operations. Infrastructure analysis reveals the domain was registered on May 14, 2026, through NICENIC INTERNATIONAL GROUP CO., LIMITED, a registrar frequently associated with malicious domains. It resolves to the IP address 172.67.133.78, which is proxied through Cloudflare, obscuring the origin server. The domain is flagged by 12 out of 95 security vendors on VirusTotal, with a Gridinsoft trust score of 0/100. It appears on three security blocklists and is actively blocked by MetaMask, PhishDestroy, and SEAL. Detection by Google Safe Browsing (GSB) is not explicitly noted, but the domain’s high-risk classification is consistent with known malicious infrastructure. The domain is currently offline, likely due to takedown efforts or the threat actor abandoning the campaign. However, the risk of re-emergence remains, as the infrastructure (registrar, hosting provider) is still accessible. Users who interacted with the domain should assume wallet compromise and take immediate action, including revoking connected dApp permissions, transferring assets to a new wallet, and monitoring for unauthorized transactions. Organizations should update blocklists to include defillaio.com and its associated IP (172.67.133.78) to prevent future exposure. Continuous monitoring of newly registered domains with similar naming patterns (e.g., typosquatting DefiLlama) is recommended to mitigate related threats.
Data Coverage
नेटवर्क सुरक्षा इंटेलिजेंस
धमकी प्रतिक्रिया पाइपलाइन
ब्लॉकलिस्ट कवरेज
10 निगरानी वाले बाहरी स्रोत · संग्रहीत स्नैपशॉट 11/08/2026
पहचान समयरेखा
-
VirusTotal
5 → 12
सहेजा गया कैप्चर
डोमेन इंटेलिजेंस
तकनीकी विवरणDNS, TLS नाम और समय-मुद्राएँ
ICANN OVERSIGHT
प्रत्यायन और आरएए संदर्भ
प्रत्यायन और आरएए संदर्भ
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
तकनीकें
3 उच्च-विश्वसनीयता वाली तकनीकें पहचानी गईं
वायरसटोटल विश्लेषण
साइट प्रदर्शन विश्लेषण
Google PageSpeed Insights — mobile performance audit of defillaio.com · checked Jun 26, 2026
क्या आप इस साइट से प्रभावित हुए?
यदि आपने खाता क्रेडेंशियल, व्यक्तिगत या भुगतान जानकारी दर्ज की है, या इस डोमेन से कोई फ़ाइल डाउनलोड की है, तो तुरंत कार्रवाई करें। घटना की रिपोर्ट करने और अपनी सुरक्षा करने में आपकी सहायता के लिए नीचे संसाधन दिए गए हैं।
अपने स्थानीय अधिकारियों को रिपोर्ट करें
आधिकारिक साइबर अपराध संपर्क, या एक शिकायत ड्राफ्ट बनाएं → प्राप्त करने के लिए अपना देश चुनें।
किसी भी डोमेन की जाँच करें
संग्रहीत ब्लॉकलिस्ट, WHOIS, DNS और सार्वजनिक स्कैन साक्ष्य का उपयोग करके खतरे का विश्लेषण
अभी स्कैन करेंफ़िशिंग की रिपोर्ट करें
संदिग्ध डोमेन हमारे थ्रेट डेटाबेस में जमा करें — समुदाय की सुरक्षा करें
रिपोर्ट करेंसीधा खतरा फीड
हाल की फ़िशिंग रिपोर्टें और उपलब्धता में परिवर्तन देखे गए
निगरानी करेंजानकारी में रहें, सुरक्षित रहें
लाइव खतरों की निगरानी करें या यदि आपको लगता है कि यह एक गलत सकारात्मक है तो इस लिस्टिंग को चुनौती दें।