bitcoinminetrix-app[.]pages[.]dev
Verifica phishing e sicurezza per bitcoinminetrix-app.pages.dev
“Bitcoin Minetrix | Stake BTCMTX On Ethereum To Mine BTC”
bitcoinminetrix-app.pages.dev — Ultimo attivo conosciuto (HTTP 200). Simulazione del marchio: Bitcoin; Tipo di truffa: Brand Impersonation. Riepilogo delle prove: VirusTotal 3/91 (alphaMountain.ai, Fortinet, Gridinsoft); 2 external blocklist matches (ScamSniffer, Enkrypt); PhishDestroy score 86/100. Registrar: Cloudflare.
L’analisi dettagliata di PhishDestroy AI resta in inglese per preservare il rapporto forense originale.
Evidence Analysis
bitcoinminetrix-app.pages.dev is a newly registered domain (created 30 April 2026) that hosts a page titled “Bitcoin Minetrix | Stake BTCMTX On Ethereum To Mine BTC”. The site is served through Cloudflare (nameservers margot.ns.cloudflare.com, mario.ns.cloudflare.com) and resolves to IP 172.66.44.77, an address associated with Cloudflare’s network in Canada. The TLS certificate is issued by Google Trust Services (WE1), indicating a valid HTTPS connection but not authenticating the underlying operator. Infrastructure fingerprinting shows the use of common front‑end libraries (Unpkg, jsDeliver, SweetAlert2, crypto‑js, CDNJS) and Google Tag Manager, as well as HTTP Strict Transport Security. Reputation metrics are extremely low: Scamadviser scores 11/100, Gridinsoft 0/100, and the domain appears on three security blocklists (PhishDestroy, ScamSniffer, Enkrypt). The listed scam type is “Brand Impersonation” targeting the Bitcoin brand, consistent with the page title that suggests a staking service for a token called BTCMTX. No malware detections have been reported by VirusTotal, but the absence of detections does not confirm safety. At present, no further content analysis is available, so the exact malicious functionality (e.g., credential harvesting, payment diversion) cannot be confirmed. Defenders should block the domain at network perimeter, add the associated IP and nameservers to deny lists, and monitor for any traffic attempting to retrieve the listed JavaScript resources. Continuous observation of Cloudflare‑derived domains with low trust scores and brand‑impersonation indicators is recommended.
Copertura dei dati13 recorded checks
Informazioni sulla sicurezza di rete
Pipeline di risposta alle minacce
Stato della lista di blocco pubblica
Tecnologie · 9 identified
SweetAlert2 is a JavaScript library that provides customisable, visually appealing, and responsive alert and modal dialog boxes for web applications.
sweetalert2.github.io Confidenza al 100%JSDelivr is a free public CDN for open-source projects. It can serve web files directly from the npm registry and GitHub repositories without any configuration.
www.jsdelivr.com Confidenza al 100%HTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org Confidenza al 100%Google Tag Manager is a tag management system (TMS) that allows you to quickly and easily update measurement codes and related code fragments collectively known as tags on your website or mobile app.
www.google.com Confidenza al 100%Cloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com Confidenza al 100%HTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org Confidenza al 100%Analisi di VirusTotal
Dati e relazioni esterneIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
Se hai inserito credenziali dell'account, informazioni personali o di pagamento oppure hai scaricato un file da questo dominio, agisci immediatamente. Di seguito sono riportate le risorse per aiutarti a segnalare l'incidente e proteggerti.
Segnalalo alle autorità locali
Seleziona il tuo Paese per ottenere contatti ufficiali del crimine informatico o creare una bozza di reclamo →.