ondo.finance.eu.com
ondo.finance.eu.com — Ultimo attivo conosciuto (HTTP 200). Riepilogo delle prove: VirusTotal 0/89; Spamhaus DBL_PHISH; PhishDestroy score 63/100. Registrar: Instra.
L’analisi dettagliata di PhishDestroy AI resta in inglese per preservare il rapporto forense originale.
Riepilogo delle prove
ondo.finance.eu.com is a tenant hostname on Instra Corporation Pty Ltd., not a separately registered domain. PhishDestroy first observed the hostname on Sep 16, 2026. Current evidence score: 63/100 (high).
One source contains a positive finding: Spamhaus DBL. Spamhaus DBL: DBL_PHISH on Sep 21, 2026 at 10:30 UTC. Non-positive and contextual checks: VirusTotal recorded 0 detections among 89 engines on Sep 21, 2026 at 10:11 UTC. The separate external-blocklist snapshot contained no matches on Sep 21, 2026 at 14:20 UTC. The 0/89 VirusTotal snapshot and the positive findings above are conflicting observations from different sources or collection times.
HTTP 200 was recorded on Sep 16, 2026 at 17:28 UTC. Instra Corporation Pty Ltd. is the hosting platform for this tenant, not its registrar.
Neither a page title nor a landing-page capture is stored. Only one source contains a positive finding; no second positive source is stored. The stored fields do not identify an impersonated brand or victim interaction.
Forensic History & Detection Timeline
-
Threat First Observed Sep 21, 2026 · 12:03 UTCDomain ingestion complete. Initial state is marked as alive.
Pipeline di risposta alle minacce
Stato della lista di blocco pubblica
Evasion analysis
Cloaking & traffic-distribution check
Stored crawler-versus-browser observations for this host, plus a live fingerprint check for Keitaro-style traffic distribution systems.
- Stored cloaking flag
- Not yet scanned
Analisi dei domini
Dettagli tecniciDNS, SAN SSL, timestamp
Analisi di VirusTotal
Intelligence della comunità
1 segnalazione della comunità
CategoriaPHISHING
I got phished by a fake Ondo Finance website at ondo.finance.eu.com. It looked like the real thing, so I connected my wallet and signed what I thought was a normal transaction. Instead it drained about 791 USDC from my wallet on the Linea chain and split it between two wallets th
Dati e relazioni esterne
“I got phished by a fake Ondo Finance website at ondo.finance.eu.com. It looked like the real thing, so I connected my wallet and signed what I thought was a normal transaction. Instead it drained about 791 USDC from my wallet on the Linea chain and split it between two wallets the scammer controls: 0xff227Fef31C6e6D48EcD5eAB60B4e2bF32fC060d and 0xEE03FAb04D3cE3797022E48D3D1eE1F7d08c4778. The theft transaction is 0x0b97d1b52e9bc437dea50a2d0ef52cb0efeeb4d279f4f3ddbf70a355321b9514. The scam domain”
Questo sito ti ha influenzato in qualche modo?
Se hai inserito credenziali dell'account, informazioni personali o di pagamento oppure hai scaricato un file da questo dominio, agisci immediatamente. Di seguito sono riportate le risorse per aiutarti a segnalare l'incidente e proteggerti.
Segnalalo alle autorità locali
Seleziona il tuo Paese per ottenere contatti ufficiali del crimine informatico o creare una bozza di reclamo →.
Verifica qualsiasi dominio
Analisi delle minacce utilizzando blocklist archiviate, WHOIS, DNS e prove di scansione pubblica
Scansiona oraSegnala un tentativo di phishing
Segnala i domini sospetti al nostro database delle minacce — proteggi la comunità
SegnalaFeed in tempo reale sulle minacce
Segnalazioni recenti di phishing e modifiche osservate della disponibilità
MonitoraRimani informato, rimani al sicuro
Controlla le minacce in tempo reale oppure contesta questa segnalazione se ritieni che si tratti di un falso positivo