thorvhain[.]org
“THORChain”
thorvhain.org — ढका हुआ · पहुंच योग्य (HTTP 200). घोटाले का प्रकार: Credential Phishing. साक्ष्य सारांश: VirusTotal 5/91 (alphaMountain.ai, Chong Lua Dao, CRDF, Fortinet, Gridinsoft); Spamhaus DBL_PHISH; cloaking observed; PhishDestroy score 93/100. रजिस्ट्रार: NiceNIC.
मूल फॉरेंसिक रिकॉर्ड सुरक्षित रखने के लिए नीचे का विस्तृत PhishDestroy AI विश्लेषण अंग्रेज़ी में रखा गया है।
This domain, thorvhain.org, is flagged as a crypto credential theft site specifically targeting THORChain users. Analysis of the page title and infrastructure reveals an attempt to impersonate the legitimate THORChain decentralized exchange platform, likely aiming to harvest wallet credentials or private keys from unsuspecting users. No drainer kit signatures were detected in the initial scan, but the domain's structure and branding align with known credential theft campaigns in the cryptocurrency sector. Infrastructure analysis reveals the following technical indicators: the domain was registered on February 21, 2026, through NiceNIC International Group Co., Limited, and currently resolves to IP address 172.67.132.104. At the time of assessment, VirusTotal reported 0/95 detections, indicating no antivirus engines had flagged the domain as malicious. The domain appears on one security blocklist and is protected by an SSL certificate issued by Google Trust Services. Detected technologies include Node.js, Express, Cloudflare Browser Insights, Cloudflare, and HTTP/3, suggesting a modern, obfuscated hosting setup designed to evade detection. The domain has been taken offline, likely in response to security interventions or automated takedown processes. Despite its current offline status, the infrastructure remains a potential risk due to its recent registration date (future-dated, possibly indicative of bulk registration for malicious use) and the use of Cloudflare to mask origin servers. Users who interacted with thorvhain.org prior to takedown should assume credential compromise and take immediate action: revoke any connected wallet sessions, monitor for unauthorized transactions, and rotate private keys if exposure is suspected. Continuous monitoring of related domains registered through the same registrar is recommended, as threat actors often re-deploy infrastructure under similar naming conventions.
नेटवर्क सुरक्षा इंटेलिजेंस Registrar context
धमकी प्रतिक्रिया पाइपलाइन
सार्वजनिक ब्लॉकलिस्ट स्थिति
सहेजा गया कैप्चर
डोमेन इंटेलिजेंस
तकनीकी विवरणडीएनएस, एसएसएल एसएएन, टाइमस्टैम्प
ICANN OVERSIGHT
प्रत्यायन और आरएए संदर्भ
प्रत्यायन और आरएए संदर्भ
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Latest Classified Outcome 2026-08-16 02:48:07 UTC
तकनीकें · 5 identified
Node.js is an open-source, cross-platform, JavaScript runtime environment that executes JavaScript code outside a web browser.
nodejs.org 100% विश्वासExpress is a web application framework for Node.js, released as free and open-source software under the MIT License. It is designed for building web applications and APIs.
expressjs.com 100% विश्वासCloudflare Browser Insights is a tool that measures the performance of websites from the perspective of users.
www.cloudflare.com 100% विश्वासCloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com 100% विश्वासHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100% विश्वासवायरसटोटल विश्लेषण
संग्रहीत साक्ष्य
साइट प्रदर्शन विश्लेषण
Google PageSpeed Insights — mobile performance audit of thorvhain.org · checked Jun 27, 2026
साक्ष्य और बाहरी रिपोर्टें
क्या आप इस साइट से प्रभावित हुए?
यदि आपने खाता क्रेडेंशियल, व्यक्तिगत या भुगतान जानकारी दर्ज की है, या इस डोमेन से कोई फ़ाइल डाउनलोड की है, तो तुरंत कार्रवाई करें। घटना की रिपोर्ट करने और अपनी सुरक्षा करने में आपकी सहायता के लिए नीचे संसाधन दिए गए हैं।
अपने स्थानीय अधिकारियों को रिपोर्ट करें
आधिकारिक साइबर अपराध संपर्क, या एक शिकायत ड्राफ्ट बनाएं → प्राप्त करने के लिए अपना देश चुनें।
किसी भी डोमेन की जाँच करें
संग्रहीत ब्लॉकलिस्ट, WHOIS, DNS और सार्वजनिक स्कैन साक्ष्य का उपयोग करके खतरे का विश्लेषण
अभी स्कैन करेंफ़िशिंग की रिपोर्ट करें
संदिग्ध डोमेन हमारे थ्रेट डेटाबेस में जमा करें — समुदाय की सुरक्षा करें
रिपोर्ट करेंसीधा खतरा फीड
हाल की फ़िशिंग रिपोर्टें और उपलब्धता में परिवर्तन देखे गए
निगरानी करेंजानकारी में रहें, सुरक्षित रहें
लाइव खतरों की निगरानी करें या यदि आपको लगता है कि यह एक गलत सकारात्मक है तो इस लिस्टिंग को चुनौती दें।