MALICIOUS — CRITICAL
gptscan[.]fun
4 of 91 security engines flagged the domain; 2 public blocklists listed it (MetaMask, SEAL); the latest stored check returned HTTP 502.
- VirusTotal
- 4/91
- Blocklists
- 2 · MetaMask, SEAL
- Disponibilità
- Ammantato · raggiungibile · HTTP 502
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
gptscan.fun — Ammantato · raggiungibile (HTTP 502). Simulazione del marchio: Amazon; Tipo di truffa: Crypto Drainer. Riepilogo delle prove: VirusTotal 4/91 (alphaMountain.ai, CRDF, Gridinsoft, SOCRadar); 2 external blocklist matches (MetaMask, SEAL); cloaking observed; PhishDestroy score 85/100. Registrar: NameCheap.
L’analisi dettagliata di PhishDestroy AI resta in inglese per preservare il rapporto forense originale.
Evidence Digest
gptscan.fun has a stored critical classification with an evidence score of 85/100. 4 of 91 security engines flagged the domain; 2 public blocklists listed it (MetaMask, SEAL). Registered 28 Apr 2026 via NameCheap, Inc., hosted on 172.67.183.165 (Cloudflare, Inc., CA). The latest stored check on 9 Aug 2026 returned HTTP 502 and includes a capture. 1 outgoing abuse report is recorded, most recently on 28 Apr 2026.
Stored generated summary (templated)mistral · 28/04/2026
Retained for the record. This text repeats stored detection facts and is not presented as authored analysis.
PhishDestroy identifies gptscan.fun as a live crypto drainer masquerading as an incident archive for Sam Altman and ChatGPT, leveraging brand impersonation to deceive users into connecting wallets or divulging sensitive credentials. This domain, registered through Namecheap Inc on April 28, 2026, resolves to 172.67.183.165 and currently evades detection with a clean VirusTotal score of 0 detections out of 95 engines. The absence of blocklist flags and use of a legitimate Let’s Encrypt SSL certificate further enhance its credibility, increasing the risk of successful exploitation.
Technical indicators reveal a newly minted domain with no historical reputation, deployed specifically to capitalize on trending AI narratives. The page title, GPTSCAN - Sam Altman & ChatGPT Incident Archive, is crafted to mislead users seeking authoritative updates, while the infrastructure’s anonymity—evidenced by the registrar choice and fresh IP allocation—suggests an opportunistic campaign targeting cryptocurrency holders. Despite zero detections, the domain’s behavior aligns with known crypto-draining tactics, including fake incident tracking and fabricated narratives to prompt wallet connections.
Users who visited gptscan.fun should immediately disconnect any connected wallets, revoke any unintended token approvals via tools like revoke.cash, and scan their devices for malware or browser extensions that may capture sensitive data. Report the domain to your security team or block it via DNS/network controls. Monitor wallet transactions closely and consider rotating private keys if exposure occurred. Exercise caution with any domain referencing AI incidents—validate sources through official channels before engagement.
Copertura dei dati12 recorded checks
Pipeline di risposta alle minacce
Stato della lista di blocco pubblica
Acquisizione salvata
Analisi dei domini
Dettagli tecniciDNS, SAN SSL, timestamp
ICANN OVERSIGHT
Accreditamento e contesto RAA
Accreditamento e contesto RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Tecnologie · 6 identified
Node.js is an open-source, cross-platform, JavaScript runtime environment that executes JavaScript code outside a web browser.
nodejs.org Confidenza al 100%Vue.js is an open-source model–view–viewmodel JavaScript framework for building user interfaces and single-page applications.
vuejs.org Confidenza al 100%Cloudflare Browser Insights is a tool that measures the performance of websites from the perspective of users.
www.cloudflare.com Confidenza al 100%Cloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com Confidenza al 100%HTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org Confidenza al 100%Analisi di VirusTotal
Analisi delle prestazioni del sito
Google PageSpeed Insights — mobile performance audit of gptscan.fun · checked Apr 28, 2026
Dati e relazioni esterneIndependent lookups and source reports
PD-20260428-6254C8 Recipient: abuse@namecheap.com Victim safety and official reportingImmediate actions and verified reporting channels
Se hai inserito credenziali dell'account, informazioni personali o di pagamento oppure hai scaricato un file da questo dominio, agisci immediatamente. Di seguito sono riportate le risorse per aiutarti a segnalare l'incidente e proteggerti.
Segnalalo alle autorità locali
Seleziona il tuo Paese per ottenere contatti ufficiali del crimine informatico o creare una bozza di reclamo →.