MALICIOUS — CRITICAL
relopayapp[.]com
relopayapp.com has been flagged under an ongoing cryptocurrency drainer and credential theft investigation.
- VirusTotal
- 4/91
- Blocklists
- 2 · MetaMask, SEAL
- उपलब्धता
- ढका हुआ · पहुंच योग्य · HTTP 502
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
relopayapp.com — ढका हुआ · पहुंच योग्य (HTTP 502). ब्रांड प्रतिरूपण: Apple; घोटाले का प्रकार: Crypto Drainer. साक्ष्य सारांश: VirusTotal 4/91 (alphaMountain.ai, CRDF, Gridinsoft, SOCRadar); URLQuery 1 alert; 2 external blocklist matches (MetaMask, SEAL); cloaking observed; PhishDestroy score 78/100. रजिस्ट्रार: Global Domain Group.
मूल फॉरेंसिक रिकॉर्ड सुरक्षित रखने के लिए नीचे का विस्तृत PhishDestroy AI विश्लेषण अंग्रेज़ी में रखा गया है।
Evidence Analysis
relopayapp.com has been flagged under an ongoing cryptocurrency drainer and credential theft investigation. This domain leverages brand impersonation tactics, likely targeting finance or payment processing users. No confirmed drainer kit signatures were observed in initial sandbox analysis, though the payload delivery mechanism remains under scrutiny. Technical indicators reveal a newly registered domain created on April 20, 2026, at 00:00 UTC, registered through Global Domain Group LLC using a Let's Encrypt SSL certificate. The infrastructure resolves to IP 188.114.96.3, which has not been previously associated with known cryptocurrency drainers in VirusTotal's detection feed. Current detection rate stands at 2/95 on VirusTotal, with no active entries in Google Safe Browsing (GSB) or major threat intelligence blocklists at time of analysis. PhishDestroy identifies this domain as active and under active investigation with elevated risk pending further forensic evaluation. Immediate defensive actions include DNS sinkholing, intrusion detection rule deployment targeting the associated IP, and proactive user advisories. While no confirmed payload execution has been reported, the absence of prior reputation coupled with the domain's novelty and payment-themed name raises significant concern. Continuous monitoring is advised until definitive classification is achieved.
डेटा कवरेज12 recorded checks
नेटवर्क सुरक्षा इंटेलिजेंस
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Hagezi Threat Feed | trustwallet.cardsbridge.com |
malicious | Sinkholed |
धमकी प्रतिक्रिया पाइपलाइन
सार्वजनिक ब्लॉकलिस्ट स्थिति
सहेजा गया कैप्चर
डोमेन इंटेलिजेंस
तकनीकी विवरणडीएनएस, एसएसएल एसएएन, टाइमस्टैम्प
ICANN OVERSIGHT
प्रत्यायन और आरएए संदर्भ
प्रत्यायन और आरएए संदर्भ
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
तकनीकें · 4 identified
Conversion-tracking pixel by Meta — logs page views and custom events to Facebook/Instagram ad accounts.
www.facebook.comPerformance monitoring tool that measures website speed from real users.
www.cloudflare.comWeb infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
वायरसटोटल विश्लेषण
साइट प्रदर्शन विश्लेषण
Google PageSpeed Insights — mobile performance audit of relopayapp.com · checked Apr 20, 2026
साक्ष्य और बाहरी रिपोर्टेंIndependent lookups and source reports
“Suspected Trust Wallet brand impersonation / cryptocurrency scam landing page. Reported domain: relopayapp.com. Reported URL: https://relopayapp.com/?utm_medium=paid&utm_source=ig&utm_id=120244407733740551&utm_content=120244407879180551&utm_term=120244407879160551&utm_campaign=120244407733740551&fbclid=PAZXh0bgNhZW0BMABhZGlkAasxpxnUt2dzcnRjBmFwcF9pZA8xMjQwMjQ1NzQyODc0MTQAAadFpQjv8NAqhNX1hoD-I7DwLzbeLFqKPxT0EWBx1F5qvhRvr80s5ajcksNujw_aem_1VDMs9OhOwXhQgbFcYlusw. Reported path/query: /?utm_medium=p”
PD-20260420-B7748F Recipient: abuse@globaldomaingroup.com Victim safety and official reportingImmediate actions and verified reporting channels
यदि आपने खाता क्रेडेंशियल, व्यक्तिगत या भुगतान जानकारी दर्ज की है, या इस डोमेन से कोई फ़ाइल डाउनलोड की है, तो तुरंत कार्रवाई करें। घटना की रिपोर्ट करने और अपनी सुरक्षा करने में आपकी सहायता के लिए नीचे संसाधन दिए गए हैं।
अपने स्थानीय अधिकारियों को रिपोर्ट करें
आधिकारिक साइबर अपराध संपर्क, या एक शिकायत ड्राफ्ट बनाएं → प्राप्त करने के लिए अपना देश चुनें।