Cerca i domini monitorati ed esamina le prove archiviate, i rilevamenti e gli ultimi dati relativi alla disponibilità osservata.
219,808
Totale monitorato
213,476
VT rilevato
91,913
Ultima visualizzazione: attivo
127,895
Non disponibile all'ultimo controllo
570
VT In attesa di conferma
How This Attack Works
Fake Token Presale scams trick victims into believing they are investing in legitimate cryptocurrency projects. Here's how the scam typically unfolds:
STEP 1
Create Fake Websites
Scammers set up realistic-looking websites mimicking legitimate token presale portals.
STEP 2
Promote Presale on Social Media
Using social media and fake endorsements, scammers attract potential investors.
STEP 3
Collect Cryptocurrency
Victims are prompted to send cryptocurrency to a specified address under the guise of buying tokens.
STEP 4
Disappear with Funds
Once funds are collected, scammers shut down the site and disappear, leaving victims without recourse.
Technical Analysis
Fake Token Presale scams often leverage phishing tactics combined with cryptocurrency-specific techniques. Attackers use homograph attacks to create URLs that closely resemble legitimate sites, often registered through top registrars like NICENIC INTERNATIONAL GROUP CO., LIMITED and PDR Ltd. d/b/a PublicDomainRegistry.com. They exploit the decentralized nature of blockchain networks, utilizing smart contracts that mimic legitimate presale contracts but are programmed to divert funds to the attacker’s wallet. The infrastructure often involves cloud-based hosting services to quickly deploy and dismantle sites, minimizing the chance of detection. HTML and JavaScript are commonly used to create dynamic, convincing interfaces that reassure potential victims of the site’s legitimacy. Additionally, attackers might deploy SEO techniques to improve the visibility of their fraudulent sites in search engine results, further increasing their reach.
Real Cases
CryptoX Presale Scam (2024)
$2 million stolen
A fake presale for a non-existent token, CryptoX, duped investors into contributing significant sums.
TokenLaunch Fraud (2023)
$1.5 million stolen
Victims were lured into a fake token launch with promises of high returns, only for the site to vanish post-collection.
QuickCoin Deception (2024)
$3 million stolen
Scammers created a sophisticated site mimicking a known exchange, leading to substantial financial losses.
How to Detect
Controlla for slight misspellings in domain names.
Look for inconsistent branding or layout compared to legitimate sites.
Be wary of unsolicited investment opportunities via social media.
Verify presale details on official project channels.
Beware of high-pressure tactics urging immediate investment.
How to Protect Yourself
1
Always verify URLs before entering personal information.
2
Use browser extensions to detect phishing attempts.
3
Consult official project websites or channels for presale information.
4
Enable two-factor authentication on cryptocurrency exchanges.
5
Relazione suspicious sites to authorities and platforms like PhishDestroy.
Frequently Asked Questions
Data sourced from PhishDestroy threat intelligence database — 689 domains tracked for this threat type
Fake Token Presale 689 domains

bitcoinhyper.network

bitcoinhyper.us

bitcoinhyperresolves.netlify.app

blockdag-network-en.web.app

blockdagnetwork.io

blockdagnetwork.net

blockdagnetwork.web.app

btfd.io

cgx.info

claim-flockerz-com.pages.dev

collectfoundation.com

flockerzclaim-5cv.pages.dev

fulent.xyz

gr0k2025.live

gr0k2025.net

gro25b-cointelegraph.com

gro25b.com

gro25b.org

gro39k-cointelegraph.com

gro75k-cointelegraph.com

gro75k.com

gro77z.org

grok27n.com

grok35k.net

grok65glaunch.com

grok65gsale.com

grok87k.net

grokvitrium.net

ionixblockchain.com

kadven.pro

layerbtcais.pages.dev

littelpepe.com

littleipepe.xyz

littlepepe.live

meteoracheck.live

miningmai.com

monoprotocol.live

officialmagacoin.io

opz-io.xyz

pepeenode-io.pages.dev

pepeheimer-claim.pages.dev

peperider.com

presale-jesse-9kw.pages.dev

presale-jessecoinvip.pages.dev

presale99bitcoins.pages.dev

presaleremittix.com

solanexai-axy.pages.dev

spcx30b.com

spcx30b.net

spx30b.com

spx99x.org

spxpresale-cryptoslate.com

spxpresale-fxempire.com

thetokencentral.com

vro105ry.pages.dev

wallitiqcard.com

wallstreetpepclaim.pages.dev

wallstreetpepesale.pages.dev

xa28r.org

xaicore.net

zcfo2r2.pages.dev

bdag.club

bestwallettoken-sales.pages.dev

bestwallettoken.crescentnetworks.co.ke

bitcoinhypertoken-ai.web.app

bitcoins-hyper.pages.dev

bl0ckdaq.network

blastuptoken.github.io

buy-pepeheimer.io

chanbnb.xyz

claim.lilpepetoken.dev

claimflockerz.pages.dev

cloudflare-frontend-9xj.pages.dev

cysicpresale.xyz

dep48k.com

dep48k.net

donk-meme.pages.dev

flockerz-dh1.pages.dev

gro25b.net

gro31q.com

gro75k.info

gro75k.org

gro79a.com

grok20g.net

grok25h-fxempire.com

grok35k-cointelegraph.com

grok35k.com

grok49k-fxempire.com

grok49k.net

grok87k-fxempire.com

groknetwork.net

helioschain.net
Pipeline di risposta alle minacce
Come vengono verificati tutti i domini presenti in questo hub e come vengono neutralizzate le minacce confermate. Visualizzazione completa della pipeline →
Controlli relativi alle informazioni sulle minacce— ogni dominio viene analizzato e sottoposto a verifica incrociata rispetto a:
urlscan.ioScreenshot · DOM · HTTPVirusTotal90+ AV enginesGoogle Safe BrowsingTransparency RelazioneCloudflare RadarDNS · certs · categoriesAlienVault OTXThreat-intel pulsesWayback MachineHistorical evidenceabuse.ch ThreatFoxIOC correlationcrt.shCertificate TransparencyDNS Sicurezza FiltersQuad9 · AdGuard · CleanBrowsingWeb-ControllaFull surface scan
Sincronizzazione globale dei fornitori— i rilevamenti confermati vengono trasmessi a 29 partner:
GoogleSafe BrowsingGoogleWeb Risk APIMicrosoftSmartScreenVirusTotalDetection feedCloudflareRadar / 1.1.1.1YandexSafe BrowsingURLScan.ioPublic scanESETWebGuardBitdefenderThreat exchangeNortonSafe WebSymantecRecensione del sitoAviraCloud detectionAvast / AVGWeb ShieldKasperskyOpenTIPDr.WebOnline scannerNetcraftRimozione APIPhishTankVerified voteAPWG eCXBulk feedPhishStatsOpen feedPhish.RelazioneHosting abuseSpamhausDBL feedPolySwarmMarketplaceCheckPhishBolster scanQutteraMalware scanURLquerySandboxCriminal IPAsset intelCRDFThreat CenterScamadviserTrust scoreMyWOTWeb of Trust