MALICIOUS — CRITICAL
invoice-system[.]invoice-ads-program[.]com
This domain, invoice-system.invoice-ads-program.com, is a live crypto-drainer phishing page designed to trick visitors into connecting a cryptocurrency wallet and silently draining funds.
- VirusTotal
- 23/91
- Blocklists
- No stored match
- उपलब्धता
- सामग्री अनुपलब्ध · HTTP 502
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
invoice-system.invoice-ads-program.com — सामग्री अनुपलब्ध (HTTP 502). ब्रांड प्रतिरूपण: Facebook; घोटाले का प्रकार: Crypto Drainer. साक्ष्य सारांश: VirusTotal 23/91 (ADMINUSLabs, Criminal IP, alphaMountain.ai, BitDefender, Chong Lua Dao); URLQuery 5 alerts; URLScan malicious verdict; Spamhaus DBL_PHISH; CF Radar malicious; PhishDestroy score 95/100. रजिस्ट्रार: Gransy, s.r.o.
मूल फॉरेंसिक रिकॉर्ड सुरक्षित रखने के लिए नीचे का विस्तृत PhishDestroy AI विश्लेषण अंग्रेज़ी में रखा गया है।
Evidence Analysis
This domain, invoice-system.invoice-ads-program.com, is a live crypto-drainer phishing page designed to trick visitors into connecting a cryptocurrency wallet and silently draining funds. It impersonates an official invoice or ads-program portal while prompting wallet connections under the guise of “processing payments” or “verifying accounts.” Once a wallet is linked, malicious scripts execute unauthorized transfers to attacker-controlled addresses, often using chain-hopping bridges to obscure the trail. Visitors should treat any unexpected “invoice” or “ads payout” link with extreme caution to avoid irreversible losses. PhishDestroy identifies this domain as actively malicious. VirusTotal’s latest scan shows 16 of 95 participating security vendors have flagged the site as harmful. Domain registration records reveal it was created on April 23, 2026, just days ago, and is currently routed through Gransy, s.r.o., resolving to IP address 162.159.140.98. Its SSL certificate is issued by Google Trust Services, which does not guarantee legitimacy—malicious actors routinely obtain valid certificates to appear trustworthy. If you visited this site or connected a wallet, disconnect it from the internet immediately and revoke any suspicious permissions using your wallet’s official access portal. Transfer remaining assets to a newly generated wallet on a clean device. Scan your system with reputable antivirus and password managers to check for compromise. Report the wallet addresses and any transaction hashes to the relevant blockchain explorers and your local cybercrime unit. Always verify links via PhishDestroy or trusted security sources before interacting with financial portals.
डेटा कवरेज12 recorded checks
नेटवर्क सुरक्षा इंटेलिजेंस
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Cloudflare DNS | invoice-system.invoice-ads-program.com |
malicious | Sinkholed |
| OpenDNS | invoice-system.invoice-ads-program.com |
phishing | Phishing Block |
| Hagezi Threat Feed | invoice-system.invoice-ads-program.com |
malicious | Sinkholed |
| DigiCert UltraDNS | invoice-system.invoice-ads-program.com |
malicious | Sinkholed |
| DNS4EU | invoice-system.invoice-ads-program.com |
malicious | Sinkholed |
धमकी प्रतिक्रिया पाइपलाइन
सार्वजनिक ब्लॉकलिस्ट स्थिति
सहेजा गया कैप्चर
डोमेन इंटेलिजेंस
तकनीकी विवरणडीएनएस, एसएसएल एसएएन, टाइमस्टैम्प
ICANN OVERSIGHT
Registration: invoice-ads-program.com
प्रत्यायन और आरएए संदर्भ
प्रत्यायन और आरएए संदर्भ
Registrar accreditation and DNS abuse obligations
For the registrable domain invoice-ads-program.com behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
तकनीकें · 6 identified
Node.js is an open-source, cross-platform, JavaScript runtime environment that executes JavaScript code outside a web browser.
nodejs.org 100% विश्वासReact is an open-source JavaScript library for building user interfaces or UI components.
reactjs.org 100% विश्वासNext.js is a React framework for developing single page Javascript applications.
nextjs.org 100% विश्वासCloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com 100% विश्वासHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100% विश्वासवायरसटोटल विश्लेषण
साइट प्रदर्शन विश्लेषण
Google PageSpeed Insights — mobile performance audit of invoice-system.invoice-ads-program.com · checked May 1, 2026
साक्ष्य और बाहरी रिपोर्टेंIndependent lookups and source reports
PD-20260501-AB04F7 Recipient: abuse@regtons.com Victim safety and official reportingImmediate actions and verified reporting channels
यदि आपने खाता क्रेडेंशियल, व्यक्तिगत या भुगतान जानकारी दर्ज की है, या इस डोमेन से कोई फ़ाइल डाउनलोड की है, तो तुरंत कार्रवाई करें। घटना की रिपोर्ट करने और अपनी सुरक्षा करने में आपकी सहायता के लिए नीचे संसाधन दिए गए हैं।
अपने स्थानीय अधिकारियों को रिपोर्ट करें
आधिकारिक साइबर अपराध संपर्क, या एक शिकायत ड्राफ्ट बनाएं → प्राप्त करने के लिए अपना देश चुनें।