labsautoprotocol[.]co
“labsprotocol”
labsautoprotocol.co — Terselubung · dapat dijangkau. Peniruan identitas merek: Avalanche; Jenis penipuan: Wallet/seed Phishing. Ringkasan bukti: VirusTotal 8/93 (alphaMountain.ai, CRDF, CyRadar, Kaspersky, SOCRadar); 3 external blocklist matches (Polkadot, Enkrypt, Codeesura); cloaking observed; PhishDestroy score 74/100. Registrar: NameCheap.
Analisis terperinci PhishDestroy AI di bawah tetap berbahasa Inggris untuk menjaga catatan forensik asli.
Analysis of labsautoprotocol.co indicates a brand‑impersonation operation targeting Avalanche users. The domain was registered on 21 February 2026 through NameCheap, Inc. and uses the registrar‑provided nameservers dns1.registrar-servers.com and dns2.registrar-servers.com. DNS resolution points to IP address 216.24.57.1, which belongs to AS397273 (Render) and is geolocated in the United States. The host presents a valid Let's Encrypt certificate (R12), suggesting the site was reachable over HTTPS before being taken offline. Threat intelligence flags the domain as a wallet/seed phishing site.
The page title returned by the server is “labsprotocol”, which does not directly reference the targeted brand but the intelligence explicitly lists Avalanche as the impersonated brand. Eight of ninety‑three VirusTotal scanners flagged the domain, confirming malicious behavior. Independent blocklists from PhishDestroy, Polkadot, Enkrypt and Codeesura have already added the domain, and it appears on four additional security blocklists, reinforcing the consensus that the site is malicious. Gridinsoft assigns a trust score of 0 / 100, indicating no reputable activity.
Current status is offline, preventing immediate interaction, but the infrastructure components remain observable. Defenders should continue to block the domain at perimeter and DNS layers, monitor the associated IP address for any resurgence, and add the IP to threat‑intel feeds. Because the domain leverages a legitimate SSL certificate, future impersonation campaigns may reuse the same certificate authority, so TLS‑inspection policies should be verified. Analysts should also watch for newly registered domains that resolve to the same AS or share the same registrar, as these may be part of a broader campaign targeting Avalanche wallet credentials.
Alur Tanggapan Ancaman Pipeline
Status Daftar Blokir Publik
Analisis VirusTotal
Bukti Terarsip
Bukti & Laporan Eksternal
Apakah Anda Terpengaruh oleh Situs Ini?
Jika Anda memasukkan kredensial akun, informasi pribadi atau pembayaran, atau mengunduh file dari domain ini, segera ambil tindakan. Di bawah ini adalah sumber daya untuk membantu Anda melaporkan insiden tersebut dan melindungi diri Anda sendiri.
Laporkan kepada Pihak Berwenang di Daerah Anda
Pilih negara Anda untuk mendapatkan kontak resmi kejahatan dunia maya, atau membuat draf pengaduan →.
Periksa Domain Apa Pun
Analisis ancaman menggunakan daftar blokir yang disimpan, WHOIS, DNS, dan bukti pemindaian publik
Pindai SekarangLaporkan Phishing
Laporkan domain yang mencurigakan ke basis data ancaman kami — lindungi komunitas
LaporanPemberitahuan Ancaman Real-Time
Laporan phishing terbaru dan perubahan ketersediaan yang diamati
PantauTetap Terinformasi, Tetap Aman
Pantau ancaman secara langsung atau ajukan keberatan terhadap daftar ini jika Anda yakin ini merupakan false positive