Lompat ke laporan keamanan
Checked 09/08/2026 Ref 164F11BD

MALICIOUS — CRITICAL

anavira[.]com

This domain, anavira.com, is actively distributing crypto drainer malware designed to automatically siphon digital assets from connected wallets.

88/100 evidence score · Critical
VirusTotal
6/91
Blocklists
No stored match
Ketersediaan
Terakhir diketahui aktif · HTTP 200
2026-02-25 01:20 UTCTerakhir diketahui aktif · HTTP 200

Do not enter credentials, seed phrases, payment details, or personal information on this domain.

⚠️
Domain ini telah ditandai sebagai berbahaya
Mesin keamanan melaporkan deteksi: 6. Berhati-hatilah — jangan memasukkan kredensial atau informasi pribadi.
Jump to section
Ringkasan laporan

anavira.com — Terakhir diketahui aktif (HTTP 200). Jenis penipuan: Crypto Drainer. Ringkasan bukti: VirusTotal 6/91 (ADMINUSLabs, ChainPatrol, alphaMountain.ai, Chong Lua Dao, ESET); PhishDestroy score 88/100. Registrar: Tucows.

Analisis terperinci PhishDestroy AI di bawah tetap berbahasa Inggris untuk menjaga catatan forensik asli.

Evidence Analysis

Ref 164F11BD

This domain, anavira.com, is actively distributing crypto drainer malware designed to automatically siphon digital assets from connected wallets. Analysis indicates the site employs deceptive tactics, such as fake token airdrops or wallet verification prompts, to trick users into authorizing malicious transactions. Once permissions are granted, the drainer executes unauthorized transfers, often emptying wallets within seconds. The threat is particularly dangerous for users of decentralized finance platforms or those holding cryptocurrency in hot wallets. Infrastructure analysis reveals multiple red flags confirming the malicious nature of this domain. Anavira.com was registered on March 30, 2019, through Tucows Domains Inc., and currently resolves to the IP address 20.62.253.20. The domain appears on two security blocklists and is flagged by 5 out of 95 security vendors on VirusTotal, including detections for phishing and malware distribution. Additionally, it is listed in three AlienVault OTX threat intelligence pulses, further corroborating its association with malicious activity. The site’s SSL certificate, issued by Let’s Encrypt, does not mitigate the risk, as threat actors frequently use valid certificates to lend false legitimacy to phishing infrastructure. If you have visited anavira.com or interacted with its content, immediate action is required to mitigate potential damage. First, disconnect any wallets or browser extensions linked to the site and revoke all permissions granted to unknown or suspicious smart contracts using a blockchain explorer. Scan your device with updated security software to detect and remove any malware that may have been downloaded. Monitor your wallet transactions for unauthorized activity and consider transferring remaining assets to a new, secure wallet if compromise is suspected. Report the domain to relevant security platforms to aid in broader threat mitigation efforts.

VirusTotal
VirusTotal
6 det.
OTX references
DNS Security
3/13
URLScan
URLScan
ScamAdviser
Scamadviser
41/100
Sertifikat TLS
Kedaluwarsa atau belum diverifikasi -196d
Usia
7.4 yr
Status terpantau
Terakhir diketahui aktif 200
PhishDestroy
Daftar Hapus
Terdaftar
Cakupan data13 recorded checks
VirusTotal 6 / 91 URLQuery laporan disimpan — putusan terperinci menunggu keputusan PhishStats tidak diperiksa OTX 3 community references CF Radar scan completed URLScan capture laporan yang disimpan URLScan verdict Analisis selesai Pemblokiran DNS 3/13 TLS Kedaluwarsa atau belum diverifikasi WHOIS 90 mo old Tangkapan layar 2 captures · 2 sources Rantai pengalihan tidak diselidiki Scamadviser 41/100
Sinyal Keamanan
SA Scamadviser Warnings 41/100
The identity of the owner of the website is hidden on WHOIS The Tranco rank (how much traffic) is rather low The server of the site has several low reviewed other websites We did not find a lot of websites linking to this site We did not find reviews on popular review sites Words were found often used by scammers
This website offers payment methods which offer a "money back services" Online shopping features were detected (use our shopping scam checklist) The site has been set-up several years ago
Intelijen Keamanan Jaringan
DNS Provider Blocks 3 / 13
Controld Adblock Controld Family Quad9 Secure
SSL Certificate Invalid
SSL certificate is invalid or expired. Issuer: Let's Encrypt

Alur Tanggapan Ancaman Pipeline

Penemuan
Checks
Reports
Ketersediaan
14/16

Status Daftar Blokir Publik

Tangkapan tersimpan

Judul Halaman
Under Construction
Sertifikat TLS
Kedaluwarsa atau belum diverifikasi · Diterbitkan oleh Let's Encrypt

Intelijen Domain

Domain
URLScan Verdict Analisis selesai score 0 report ↗
Server / ASN LiteSpeed · AS8075 MICROSOFT-CORP-MSN-AS-BLOCK, US
Reputasi IP abuse score 0/100 0 reports checked 30/07/2026
Alamat IP 20.62.253.20 US
LokasiUS Washington, US
JaringanAS8075 · Microsoft Corporation
PendaftaranDibuat 30/03/2019 Expires 30/03/2026
Elapsed Since First Report 83 days
Yang kami hitung Raw elapsed time since the first stored abuse report. It is not a registrar response-time measurement. Latest observed status: Terakhir diketahui aktif.
Isi setiap laporan Catatan laporan keluar yang disimpan dapat merujuk pada bukti yang tersedia pada saat itu, seperti keputusan vendor, data pendaftaran, detail hosting, klasifikasi, atau tangkapan layar. Halaman ini tidak menyimpulkan secara pasti muatan yang dikirimkan, penerimaan, pengakuan, atau tindakan oleh penerima.
Status HTTP200
Rincian teknisDNS, SAN SSL, cap waktu
Pertama Kali Terdeteksi22/12/2025
DOM Analysisanalyzed 11/03/2026score 88/100
IoC Extractionscanned 02/08/20260 wallet · 0 Telegram IoCs
Submitted URLhttp://anavira.com/
Server namans1.turbify.comns2.turbify.com
TLS Fingerprint
TLS Observationvalid from 14/09/2025scanned 12/03/2026
TLS SAN Domainsautodiscover.anavira.comcpanel.anavira.comcpcalendars.anavira.comcpcontacts.anavira.comwebdisk.anavira.comwebmail.anavira.com
ICANN OVERSIGHT

Akreditasi dan konteks RAA

Registrar accreditation and DNS abuse obligations

For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.

Accreditation is a contract, not a safety certification.

RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.

Accountability draft Tidak ada yang dikirim secara otomatis.
Laporkan Domain Ini Kirimkan bukti & bantu lindungi orang lain

Analisis VirusTotal

6 / Vendor keamanan 91 menandai domain ini
View on VT
Last analyzed Previous stored snapshot: 7 detections
ADMINUSLabs
ChainPatrol
alphaMountain.ai
Chong Lua Dao
ESET
Gridinsoft

Bukti Terarsip

Wayback Machine Snapshot
Cuplikan sejarah tersedia untuk tinjauan bukti
View Archive
Analisis Performa Situs

Google PageSpeed Insights — mobile performance audit of anavira.com · checked Jun 27, 2026

100
Good
Performance
FCP
0.77s
First Contentful Paint
LCP
0.77s
Largest Contentful Paint
CLS
0
Cumulative Layout Shift
TBT
0ms
Total Blocking Time
SI
1.38s
Speed Index
Powered by Google PageSpeed Insights · Mobile strategy · Scores: 90-100 Good 50-89 Needs Work 0-49 Poor
Bukti & Laporan EksternalIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
If credentials were compromised, report immediately. Do not engage with recovery scammers.

Jika Anda memasukkan kredensial akun, informasi pribadi atau pembayaran, atau mengunduh file dari domain ini, segera ambil tindakan. Di bawah ini adalah sumber daya untuk membantu Anda melaporkan insiden tersebut dan melindungi diri Anda sendiri.

Europol
Temukan saluran pelaporan resmi untuk negara UE Anda
National police directory
Waspadalah terhadap penipu yang mengatasnamakan pemulihan! Penjahat dapat menghubungi korban lagi sambil berpura-pura menjadi penyelidik, pengacara, atau agen pemulihan. Jangan membayar biaya di muka atau membagikan kredensial. Pelajari lebih lanjut tentang penipuan dalam proses pemulihan →

Laporkan kepada Pihak Berwenang di Daerah Anda

Pilih negara Anda untuk mendapatkan kontak resmi kejahatan dunia maya, atau membuat draf pengaduan →.

Direktori 97 negara
Draf yang dibantu AI — detail insiden diproses oleh penyedia AI Tinjau dan kirimkan sendiri
Sematkan Laporan IniRead-only HTML widget
HTML · IFRAME

Sematkan Laporan Ini

Bagikan informasi ancaman ini di situs web atau blog Anda

embed.html
<iframe
  src="https://phishdestroy.io/id/embed/domain/anavira.com"
  title="PhishDestroy threat report for anavira.com"
  width="100%" height="320"
  loading="lazy"
  referrerpolicy="no-referrer"
  sandbox="allow-same-origin allow-popups allow-popups-to-escape-sandbox"
  style="border:0;border-radius:12px;max-width:100%"
></iframe>

Surat Terima Kasih yang Sangat Tulus

Pembuat draf satir

Penerima
Konteks biaya

Draf satir. Angka biaya merupakan perkiraan; tidak diklaim bahwa angka tersebut secara tepat terkait dengan domain ini.