MALICIOUS — HIGH
reawake[.]world
Analysis of the domain reawake.world indicates it was operating as a phishing site targeting users of the Reawake brand, as evidenced by the page title 'Reawake' detected in infrastructure scans.
- VirusTotal
- 6/91
- Blocklists
- 2 · MetaMask, SEAL
- Ketersediaan
- Konten tidak tersedia · HTTP 502
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
reawake.world — Konten tidak tersedia (HTTP 502). Peniruan identitas merek: Discord; Jenis penipuan: Generic Phishing. Ringkasan bukti: VirusTotal 6/91 (alphaMountain.ai, Chong Lua Dao, CRDF, Fortinet, Gridinsoft); Spamhaus DBL_SPAM; 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 68/100. Registrar: Global Domain Group.
Analisis terperinci PhishDestroy AI di bawah tetap berbahasa Inggris untuk menjaga catatan forensik asli.
Evidence Analysis
Analysis of the domain reawake.world indicates it was operating as a phishing site targeting users of the Reawake brand, as evidenced by the page title 'Reawake' detected in infrastructure scans. The domain was registered on March 10, 2026, through Global Domain Group LLC and resolved to the IP address 178.16.54.253, hosted on AS202412 (Omegatech LTD) in the Netherlands. SSL certificate issued by Let's Encrypt (R12) was in use, and the site employed Node.js, Vue.js, Nuxt.js, jsDelivr, Google Analytics, and HTTP/3 technologies, suggesting a modern web stack likely designed to evade basic detection mechanisms. At the time of assessment, four out of ninety-five security vendors on VirusTotal flagged the domain as malicious.
The domain appeared on three security blocklists and was actively blocked by PhishDestroy, MetaMask, and SEAL. Nameservers ns1.virtualine.org and ns2.virtualine.org were associated with the domain. As of July 22, 2026, the domain has been taken offline, though residual DNS records may persist. Defenders should treat any residual DNS queries or cached references to reawake.world as indicators of compromise.
The use of HTTP/3 and modern JavaScript frameworks may have facilitated evasion of traditional network-based detection, necessitating endpoint-level monitoring for related artifacts. While the exact phishing mechanism remains unconfirmed due to the domain's offline status, the presence of Google Analytics suggests potential credential harvesting or user tracking. No additional brand impersonation or scam category was specified in available intelligence. Infrastructure analysis reveals a pattern consistent with short-lived phishing campaigns, and organizations should review logs for connections to 178.16.54.253 or requests to reawake.world prior to its takedown.
Cakupan data12 recorded checks
Intelijen Keamanan Jaringan
Alur Tanggapan Ancaman Pipeline
Status Daftar Blokir Publik
Tangkapan tersimpan
Intelijen Domain
Rincian teknisDNS, SAN SSL, cap waktu
ICANN OVERSIGHT
Akreditasi dan konteks RAA
Akreditasi dan konteks RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Teknologi · 6 identified
JavaScript runtime built on Chrome V8 engine for server-side development.
Progressive JavaScript framework for building user interfaces.
Hybrid Vue framework for server-side rendering and static sites.
Free public CDN for open-source projects, serving files from npm and GitHub.
Web analytics service tracking website traffic and user behavior.
marketingplatform.google.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
Analisis VirusTotal
Bukti & Laporan EksternalIndependent lookups and source reports
PD-20260310-15FBC4 Recipient: abuse@omegatech.sc Victim safety and official reportingImmediate actions and verified reporting channels
Jika Anda memasukkan kredensial akun, informasi pribadi atau pembayaran, atau mengunduh file dari domain ini, segera ambil tindakan. Di bawah ini adalah sumber daya untuk membantu Anda melaporkan insiden tersebut dan melindungi diri Anda sendiri.
Laporkan kepada Pihak Berwenang di Daerah Anda
Pilih negara Anda untuk mendapatkan kontak resmi kejahatan dunia maya, atau membuat draf pengaduan →.