MALICIOUS — CRITICAL
bridge[.]relaylink[.]app
12 of 93 security engines flagged the domain; 1 public blocklist listed it (ScamSniffer); the latest stored check returned HTTP 502.
- VirusTotal
- 12/93
- Blocklists
- 1 · ScamSniffer
- Disponibilità
- Contenuto non disponibile · HTTP 502
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
bridge.relaylink.app — Contenuto non disponibile (HTTP 502). Tipo di truffa: Crypto Scam. Riepilogo delle prove: VirusTotal 12/93 (ADMINUSLabs, ChainPatrol, alphaMountain.ai, BitDefender, CyRadar); Spamhaus DBL_PHISH; 1 external blocklist match (ScamSniffer); PhishDestroy score 88/100. Registrar: Tucows Domains.
L’analisi dettagliata di PhishDestroy AI resta in inglese per preservare il rapporto forense originale.
Evidence Analysis
The domain bridge.relaylink.app was registered through Tucows Domains Inc on 21 February 2026. The registration is recent and coincides with the appearance of a new malicious site that claims to facilitate cryptocurrency transactions. The domain resolves to the IPv4 address 23.254.225.209, which is allocated to AS54290 (Hostwinds LLC) in the Netherlands. The web server returns HTTP 200 for the landing page, whose title is “Relay Bridge”. The site presents a TLS certificate identified as R13, indicating a publicly trusted certificate but offering no validation of the service’s legitimacy. Nameservers ns1.renewyourname.net and ns2.renewyourname.net, both commonly used by disposable or rapidly‑provisioned domains, are configured for the zone. Multiple security products have flagged the domain. Gridinsoft assigns a trust score of 0 / 100, and VirusTotal records 12 detections out of 95 scanners. The domain is listed on two public blocklists—PhishDestroy and ScamSniffer—both of which categorize it as a cryptocurrency‑related scam. The internal risk rating is high, and the site remains active at the time of analysis. At present, the specific brand or service being spoofed cannot be confirmed; the page does not reference a well‑known exchange or wallet provider. Analysts should therefore treat any traffic to bridge.relaylink.app as hostile and block it at perimeter defenses. Email gateways should flag messages containing this URL, and SOC teams should monitor for credential‑harvesting attempts or malicious payloads linked to the IP address. Continuous re‑evaluation is recommended as additional indicators may surface.
Copertura dei dati12 recorded checks
Pipeline di risposta alle minacce
Stato della lista di blocco pubblica
Acquisizione salvata
Analisi dei domini
Dettagli tecniciDNS, SAN SSL, timestamp
ICANN OVERSIGHT
Registration: relaylink.app
Accreditamento e contesto RAA
Accreditamento e contesto RAA
Registrar accreditation and DNS abuse obligations
For the registrable domain relaylink.app behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Analisi di VirusTotal
Dati e relazioni esterneIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
Se hai inserito credenziali dell'account, informazioni personali o di pagamento oppure hai scaricato un file da questo dominio, agisci immediatamente. Di seguito sono riportate le risorse per aiutarti a segnalare l'incidente e proteggerti.
Segnalalo alle autorità locali
Seleziona il tuo Paese per ottenere contatti ufficiali del crimine informatico o creare una bozza di reclamo →.