MALICIOUS — CRITICAL
aa4est[.]daorel[.]ch
PhishDestroy identifies aa4est.daorel.ch as a live cryptocurrency drainer domain hosting a generic cryptocurrency wallet drainer kit.
- VirusTotal
- 12/91
- Blocklists
- No stored match
- Disponibilità
- Contenuto non disponibile · HTTP 502
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
aa4est.daorel.ch — Contenuto non disponibile (HTTP 502). Tipo di truffa: Crypto Drainer. Riepilogo delle prove: VirusTotal 12/91 (BitDefender, Chong Lua Dao, CRDF, ESET, Fortinet); URLQuery 1 alert; PhishDestroy score 90/100.
L’analisi dettagliata di PhishDestroy AI resta in inglese per preservare il rapporto forense originale.
Evidence Analysis
PhishDestroy identifies aa4est.daorel.ch as a live cryptocurrency drainer domain hosting a generic cryptocurrency wallet drainer kit. The domain leverages a recently registered subdomain under daorel.ch to host the drainer payload, which is actively serving malicious JavaScript designed to siphon funds from victims’ wallets during cryptocurrency transaction signing. No specific brand is spoofed in this campaign, indicating a broad opportunistic targeting strategy across multiple wallet providers and DeFi interfaces.
This domain was flagged during active threat hunting with the following technical indicators: SSL certificate issued by Let’s Encrypt, VirusTotal detection rate at 7/95 as of last scan, registered under Namecheap Inc., resolving to IP address 185.149.120.183 located in Switzerland (CH), and currently not listed on Google Safe Browsing (GSB). The domain was created on an unknown date but became active within the last 30 days based on passive DNS correlation. Blocklist aggregator checks show 0 current detections across public threat intelligence feeds, indicating a newly deployed and largely undetected campaign.
As of today, the campaign remains active with the domain serving live content. Immediate actions include isolating the IP 185.149.120.183 and blocking all subdomains under daorel.ch at network perimeter. Users should avoid visiting the URL and report any transactions involving this domain to their wallet provider. The current risk is assessed as HIGH due to the absence of signature-based detection and the domain’s use of a trusted SSL certificate. Full forensic indicators and IOCs are available in the associated threat report under seed d37dff.
Copertura dei dati12 recorded checks
Informazioni sulla sicurezza di rete
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| OpenDNS | aa4est.daorel.ch |
phishing | Phishing Block |
Pipeline di risposta alle minacce
Stato della lista di blocco pubblica
Tecnologie · 3 identified
HTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org Confidenza al 100%DDoS-Guard is a Russian Internet infrastructure company which provides DDoS protection, content delivery network services, and web hosting services.
ddos-guard.net Confidenza al 100%Analisi di VirusTotal
Prove archiviate
Dati e relazioni esterneIndependent lookups and source reports
PD-20260503-8410F0 Recipient: abuse@ddos-guard.net Victim safety and official reportingImmediate actions and verified reporting channels
Se hai inserito credenziali dell'account, informazioni personali o di pagamento oppure hai scaricato un file da questo dominio, agisci immediatamente. Di seguito sono riportate le risorse per aiutarti a segnalare l'incidente e proteggerti.
Segnalalo alle autorità locali
Seleziona il tuo Paese per ottenere contatti ufficiali del crimine informatico o creare una bozza di reclamo →.