Lompat ke laporan keamanan
Checked 09/08/2026 Ref 902AB8D6

MALICIOUS — CRITICAL

Pemeriksaan phishing dan keamanan poanex.com

poanex[.]com

The domain poanex.com was a generic phishing site posing as a cryptocurrency-based online casino scam.

95/100 evidence score · Critical
VirusTotal
14 detections
Blocklists
No stored match
Ketersediaan
Konten tidak tersedia · HTTP 502
2026-02-16 16:06 UTCKonten tidak tersedia · HTTP 502

Do not enter credentials, seed phrases, payment details, or personal information on this domain.

⚠️
Domain ini telah ditandai sebagai berbahaya
Mesin keamanan melaporkan deteksi: 14. Berhati-hatilah — jangan memasukkan kredensial atau informasi pribadi.
Jump to section
Ringkasan laporan

poanex.com — Konten tidak tersedia (HTTP 502). Peniruan identitas merek: Genericcrypto; Jenis penipuan: Crypto Scam. Ringkasan bukti: VirusTotal 14 detections (engine total unavailable) (ADMINUSLabs, alphaMountain.ai, BitDefender, CRDF, CyRadar); URLQuery 1 alert; URLScan malicious verdict; Spamhaus DBL_PHISH; PhishDestroy score 95/100. Registrar: NiceNIC.

Analisis terperinci PhishDestroy AI di bawah tetap berbahasa Inggris untuk menjaga catatan forensik asli.

Evidence Analysis

Ref 902AB8D6

The domain poanex.com was a generic phishing site posing as a cryptocurrency-based online casino scam. It did not impersonate a specific brand but operated under the false premise of 'Poanex: Most Popular Online Crypto Casino Based on Blockchain,' targeting users with fraudulent gambling offers to steal funds. The site is currently taken offline, but it previously utilized the Gambler Scam phishing kit to facilitate cryptocurrency theft.

Technical analysis of poanex.com reveals 14 of 95 VirusTotal security vendors flagged the domain, including ADMINUSLabs, alphaMountain.ai, and BitDefender. The domain was registered through NiceNIC International Group Co., Limited on February 21, 2026, and resolved to the IP address 104.21.57.175, hosted by Cloudflare, Inc. in the US. It appeared on one security blocklist, PhishDestroy, and had no SSL certificate. The observed HTTP status was 666, and the nameservers were arushi.ns.cloudflare.com and graham.ns.cloudflare.com. Google Safe Browsing did not flag the domain at the time of assessment.

Victims of poanex.com should immediately revoke any token approvals granted to the site and transfer remaining funds to a new cryptocurrency wallet. Monitor transaction histories for unauthorized activity and report the scam to relevant platforms, such as the Federal Trade Commission (FTC) or local cybercrime units. Additionally, users can submit the domain to security vendors like VirusTotal or blocklist providers to prevent further exploitation.

Stored source results

Recorded verdicts and infrastructure observations for this domain.

VirusTotal
VirusTotal
14 det.
URLQuery
URLQuery
1 threat alert
URLScan
URLScan
Sertifikat TLS
WE1
Status terpantau
Konten tidak tersedia 502
PhishDestroy
Daftar Hapus
Terdaftar
Reports Sent
2
Cakupan data12 recorded checks
VirusTotal 14 detections · vendor total unavailable URLQuery 1 threat-system alert PhishStats tidak diperiksa OTX no community references CF Radar scan completed URLScan capture laporan yang disimpan URLScan verdict malicious Pemblokiran DNS tidak diperiksa TLS valid certificate, 72d WHOIS not parsed Tangkapan layar 3 captures · 3 sources Rantai pengalihan tidak diselidiki
Intelijen Keamanan Jaringan Registrar context
Threat Detection Systems 1 alert
Detection System Indicator Verdict Alert
OpenDNS poanex.com phishing Phishing Block
Registrar context NiceNIC
Stored registration data identifies NICENIC INTERNATIONAL GROUP CO., LIMITED (IANA 3765) as the registrar. PhishDestroy maintains separate NiceNIC abuse-report research; registrar association is contextual and is not an independent detection for this domain.
NiceNIC Verdict Full Investigation

Alur Tanggapan Ancaman Pipeline

Penemuan
Checks
Reports
Ketersediaan
19/19
Ancaman Telah Diterima
poanex.com telah terdeteksi dan dimasukkan ke dalam antrian untuk analisis menyeluruh
16/02/2026
URLScan.io Capture
Stored URLScan report with capture artifacts
16/02/2026
URLScan Verdict
URLScan returned a malicious verdict · score 100
29/07/2026
Cloudflare Radar Report
A stored Cloudflare Radar report is available. The report link alone is not a malicious verdict and does not prove that every network field was captured.
Web Archive
Preserved in Wayback Machine — historical evidence archived
14/03/2026
VirusTotal
14 detections recorded on VirusTotal — vendor total unavailable
23/02/2026
Google Safe Browsing
03/03/2026
Registrar Context: NiceNIC
Separate registrar research is available. Registrar association is contextual and is not scored as an independent detection.
Brand Impersonation
Impersonation of Genericcrypto
Forensic Evidence Collected
Stored evidence from URLScan.io, URLQuery, stored screenshot
16/02/2026
Technical Analysis Recorded
Laporan tersebut berisi teknologi tersimpan atau hasil analisis forensik.
09/08/2026
Cloudflare Radar Scan
Dipindai dengan Cloudflare Radar; analisis jaringan selesai.
07/03/2026
Content Observed Unavailable
Pemantauan mencatat respons yang tidak tersedia (HTTP 666); penyebabnya belum diketahui secara independen.
01/03/2026
Initial Abuse Report (#1)
Sent to 3 abuse contacts at NiceNIC International Group Co., Limited with forensic evidence
abuse@nicenic.netabuse@verisign-grs.comcompliance@icann.org
03/03/2026
ICANN Escalation #2
Escalation #2 sent to 3 recipients including ICANN Compliance — follow-up record after a previous report
abuse@nicenic.netabuse@verisign-grs.comcompliance@icann.org
04/03/2026
2 Reports Filed
2 report records were stored over 159 days; current observed status: Konten tidak tersedia
Daftar yang Dihapus Telah Dipublikasikan
16/02/2026
Content Observed Unavailable
Pemeriksaan terakhir yang disimpan menunjukkan bahwa konten yang dilaporkan tidak tersedia; ini tidak menentukan siapa atau apa yang menyebabkan perubahan tersebut.
01/03/2026
Waktu hingga pertama kali tidak tersedia
298 jam berlalu dari deteksi hingga observasi pertama yang tidak tersedia.

Status Daftar Blokir Publik

Tangkapan tersimpan

Judul Halaman
Poanex: Most Popular Online Crypto Casino Based on Blockchain
Sertifikat TLS
Valid transport encryption · Diterbitkan oleh WE1 · valid for 72 days

Intelijen Domain

Domain
URLScan Verdict Berbahaya score 100 Phishing report ↗
Server / ASN cloudflare · AS13335 Cloudflare, Inc.
IP Context Cloudflare shared edge origin IP hidden Reputasi Edge-IP tidak dikaitkan dengan domain ini.
Alamat IP 104.21.57.175 CDN
LokasiUS San Francisco, US
JaringanAS13335 · Cloudflare, Inc.
IP asal tersembunyi di balik proksi CDN. Hasil IP terbalik untuk alamat edge berisi penyewa yang tidak terkait; menemukan asal memerlukan DNS pasif atau data transparansi sertifikat.
PendaftaranExpires 10/02/2027
Status HTTP502 Error
Waktu hingga pertama kali tidak tersedia 12 days
Yang kami hitung Waktu yang berlalu sejak laporan penyalahgunaan pertama kali disimpan hingga pengamatan pertama bahwa konten tersebut tidak tersedia. Hal ini tidak dapat menentukan penyebabnya.
Minimum notice count 2 is the number of stored outgoing report records for this domain. It does not by itself prove acknowledgement or action by a recipient.
Isi setiap laporan Catatan laporan keluar yang disimpan dapat merujuk pada bukti yang tersedia pada saat itu, seperti keputusan vendor, data pendaftaran, detail hosting, klasifikasi, atau tangkapan layar. Halaman ini tidak menyimpulkan secara pasti muatan yang dikirimkan, penerimaan, pengakuan, atau tindakan oleh penerima.
ICANN RAA §3.18 The history below lists stored escalation records and timestamps. It does not by itself establish receipt, acknowledgement, compliance, or enforcement by any recipient.
Rincian teknisDNS, SAN SSL, cap waktu
Pertama Kali Terdeteksi16/02/2026
DOM Analysisanalyzed 29/07/2026score 0/100
IoC Extractionscanned 02/08/20260 wallet · 0 Telegram IoCs
Submitted URLhttps://poanex.com/
Server namaarushi.ns.cloudflare.comgraham.ns.cloudflare.com
TLS Observationscanned 15/03/2026
Case ID
ICANN OVERSIGHT

Akreditasi dan konteks RAA

Registrar accreditation and DNS abuse obligations

For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.

Accreditation is a contract, not a safety certification.

RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.

Accountability draft Tidak ada yang dikirim secara otomatis.

Latest Classified Outcome 2026-08-09 04:14:12 UTC

Primary outcome Registration hold observed reason: Registrar clientHold 95% confidence
Attribution NICENIC INTERNATIONAL GROUP CO., LIMITED mechanism: Registrar clientHold source: Rdap Status Collector
Evidence layers Availability: DNS inactive Content: Unreachable DNS: NXDOMAIN Registration: Registrar clientHold
Latest HTTP observation Tidak diketahui Origin unreachable Http 5xx 20% 2026-08-09 01:36:45 UTC
RDAP registration Registrar clientHold NICENIC INTERNATIONAL GROUP CO., LIMITED · IANA 3765 RDAP HTTP 200 source: Rdap Status Collector clientDeleteProhibitedclientHoldclientTransferProhibited expires 2027-02-10 12:44:52 UTC checked 2026-08-09 04:14:12 UTC
Registrar action marker verified clientHold marker NICENIC INTERNATIONAL GROUP CO., LIMITED · IANA 3765 causal link to our report not established
Observed timeline current episode first observed: 2026-08-05 01:45:38 UTC first terminal observation: 2026-08-05 01:45:38 UTC
Availability, content, DNS and registration are independent evidence layers. NXDOMAIN, an unreachable origin or missing content alone does not prove registrar action. A registrar or provider is credited only when a direct technical marker identifies that actor. Report causality is shown separately.
Riwayat Laporan Penyalahgunaan · 2 stored reports over 2 days · click to expand
This timeline is built from stored outgoing report records. It documents timestamps and listed recipients, but does not by itself prove delivery, acknowledgement, or recipient action.
2 abuse reports filed over 159 days — latest observed status: Konten tidak tersedia
The records name NiceNIC International Group Co., Limited as a recipient or subject. ICANN Compliance appears in the recipient field for at least one record.
2
reports
159
days
ICANN CC
  1. Report #1 ICANN CC 341h still active Mar 3, 2026 · 01:46 UTC
    ESCALATION #2 (341h active): Phishing - poanex[.]com
    abuse@nicenic.net abuse@verisign-grs.com compliance@icann.org
  2. Report #2 ICANN CC 379h still active Mar 4, 2026 · 15:45 UTC
    ESCALATION #3 (379h active): Phishing - poanex[.]com
    abuse@nicenic.net abuse@verisign-grs.com compliance@icann.org
Record scope: the timeline documents outgoing records stored by PhishDestroy. Delivery, acknowledgement, and subsequent action require separate recipient or infrastructure evidence.
Laporkan Domain Ini Kirimkan bukti & bantu lindungi orang lain

Analisis VirusTotal

14 detections recorded · vendor total unavailable
View on VT
Last analyzed
ADMINUSLabs
alphaMountain.ai
BitDefender
CRDF
CyRadar
Fortinet
G-Data
Gridinsoft
Kaspersky
Lionic
Netcraft
SOCRadar
Sophos
VIPRE

Bukti Terarsip

Wayback Machine Snapshot
Cuplikan sejarah tersedia untuk tinjauan bukti
View Archive
Bukti & Laporan EksternalIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
If credentials were compromised, report immediately. Do not engage with recovery scammers.

Jika Anda memasukkan kredensial akun, informasi pribadi atau pembayaran, atau mengunduh file dari domain ini, segera ambil tindakan. Di bawah ini adalah sumber daya untuk membantu Anda melaporkan insiden tersebut dan melindungi diri Anda sendiri.

Europol
Temukan saluran pelaporan resmi untuk negara UE Anda
National police directory
Waspadalah terhadap penipu yang mengatasnamakan pemulihan! Penjahat dapat menghubungi korban lagi sambil berpura-pura menjadi penyelidik, pengacara, atau agen pemulihan. Jangan membayar biaya di muka atau membagikan kredensial. Pelajari lebih lanjut tentang penipuan dalam proses pemulihan →

Laporkan kepada Pihak Berwenang di Daerah Anda

Pilih negara Anda untuk mendapatkan kontak resmi kejahatan dunia maya, atau membuat draf pengaduan →.

Direktori 97 negara
Draf yang dibantu AI — detail insiden diproses oleh penyedia AI Tinjau dan kirimkan sendiri
Sematkan Laporan IniRead-only HTML widget
HTML · IFRAME

Sematkan Laporan Ini

Bagikan informasi ancaman ini di situs web atau blog Anda

embed.html
<iframe
  src="https://phishdestroy.io/id/embed/domain/poanex.com"
  title="PhishDestroy threat report for poanex.com"
  width="100%" height="320"
  loading="lazy"
  referrerpolicy="no-referrer"
  sandbox="allow-same-origin allow-popups allow-popups-to-escape-sandbox"
  style="border:0;border-radius:12px;max-width:100%"
></iframe>

Surat Terima Kasih yang Sangat Tulus

Pembuat draf satir

Penerima
Konteks biaya

Draf satir. Angka biaya merupakan perkiraan; tidak diklaim bahwa angka tersebut secara tepat terkait dengan domain ini.