quent0nest[.]sbs
“Ledger Wallet (ex. Ledger Live) - Crypto App | Ledger”
Riepilogo delle prove
This domain, quent0nest.sbs, operates as a crypto drainer, specifically designed to target cryptocurrency wallet users with malicious scripts that automatically siphon digital assets upon interaction. Analysis indicates the domain employs deceptive tactics, such as fake token airdrops or wallet verification prompts, to trick users into connecting their wallets. Once connected, the embedded malicious code executes unauthorized transactions, draining funds without the victim's explicit consent. The threat primarily affects users of decentralized finance platforms and non-custodial wallets, where transaction signing is required for execution. Infrastructure analysis reveals concrete evidence of malicious intent. The domain was registered on April 08, 2026, through NameSilo, LLC, a registrar frequently associated with high-risk domains due to its lenient registration policies. It resolves to the IP address 188.114.97.3, which has been linked to multiple phishing campaigns. Security vendors have flagged quent0nest.sbs on VirusTotal, with 16 out of 95 engines detecting malicious activity. Additionally, the domain appears on four security blocklists, including those maintained by MetaMask and ScamSniffer, further corroborating its classification as a high-risk threat. The Gridinsoft trust score of 0/100 underscores the domain's complete lack of credibility. Users who have visited quent0nest.sbs or interacted with its content should take immediate action to mitigate potential damage. First, disconnect any wallets that may have been linked to the domain by revoking permissions via wallet management tools or blockchain explorers. Next, transfer remaining assets to a new, secure wallet to prevent further unauthorized access. Monitor transaction histories for any suspicious activity and report the domain to relevant security platforms to aid in broader threat mitigation efforts. If funds have already been lost, file a report with local cybercrime authorities and provide all available transaction details for investigation.
Istantanea delle prove inviate
- Inviato
- Voci del registro
- 1
- ID del caso
PD-20260408-947DDF- Titolo della pagina acquisita
- Ledger Wallet (ex. Ledger Live) - Crypto App | Ledger
- Artefatto PDF
- Prova in PDF
Base giuridica
Testo completo delle prove
Illegal Activities: Active phishing operation targeting victims
Fraud & Deception: Impersonation of legitimate services
Identity Theft: Collection of credentials under false pretenses
Applicable Laws (Unknown):
International Anti-Cybercrime Regulations
Budapest Convention on Cybercrime
Universal Fraud Prevention Laws
Phishing activities violate international cybercrime conventions and Unknown's domestic fraud laws.
Action Required: This evidence-backed report demonstrates clear violations requiring suspension per your policies. Continued hosting exposes your organization to regulatory scrutiny and potential legal liability.
Data Coverage
Informazioni sulla sicurezza di rete
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DigiCert UltraDNS | quent0nest.sbs |
malicious | Sinkholed |
| Hagezi Threat Feed | quent0nest.sbs |
malicious | Sinkholed |
Pipeline di risposta alle minacce
Copertura delle blocklist
10 fonti esterne monitorate · snapshot del 12/08/2026
Acquisizione salvata
Analisi dei domini
Dettagli tecniciDNS, nomi TLS e date
ZONA SHORTDOT · PROVE PUBBLICHE
.sbs
ShortDot zone evidence
ShortDot zone evidence
The linked repository preserves daily zone observations across seven ShortDot-operated TLDs, including registration volume and abuse-related indicators. This registry context is supporting background and is not an independent detection for the domain in this report.
ICANN OVERSIGHT
Accreditamento e contesto RAA
Accreditamento e contesto RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Informazioni forensi
Analisi di VirusTotal
Analisi delle prestazioni del sito
Google PageSpeed Insights — mobile performance audit of quent0nest.sbs · checked Jun 26, 2026
Questo sito ti ha influenzato in qualche modo?
Se hai inserito credenziali dell'account, informazioni personali o di pagamento oppure hai scaricato un file da questo dominio, agisci immediatamente. Di seguito sono riportate le risorse per aiutarti a segnalare l'incidente e proteggerti.
Segnalalo alle autorità locali
Seleziona il tuo Paese per ottenere contatti ufficiali del crimine informatico o creare una bozza di reclamo →.
Verifica qualsiasi dominio
Analisi delle minacce utilizzando blocklist archiviate, WHOIS, DNS e prove di scansione pubblica
Scansiona oraSegnala un tentativo di phishing
Segnala i domini sospetti al nostro database delle minacce — proteggi la comunità
SegnalaFeed in tempo reale sulle minacce
Segnalazioni recenti di phishing e modifiche osservate della disponibilità
MonitoraRimani informato, rimani al sicuro
Controlla le minacce in tempo reale oppure contesta questa segnalazione se ritieni che si tratti di un falso positivo