rizzmas-migrate[.]lol
rizzmas-migrate.lol — Contenuto non disponibile (HTTP 502). Tipo di truffa: Crypto Drainer. Riepilogo delle prove: VirusTotal 4/91 (alphaMountain.ai, CRDF, Gridinsoft, SOCRadar); URLQuery 2 alerts; 1 external blocklist match (ScamSniffer); PhishDestroy score 71/100. Registrar: Hostinger.
L’analisi dettagliata di PhishDestroy AI resta in inglese per preservare il rapporto forense originale.
PhishDestroy identifies rizzmas-migrate.lol as a high-risk crypto drainer domain designed to trick users into connecting cryptocurrency wallets under the guise of a migration service. This domain mimics legitimate blockchain migration tools to deceive visitors into authorizing malicious transactions that drain funds directly from connected wallets. The threat is particularly insidious because it exploits the urgency of migration processes, where users may overlook security checks when attempting to move assets between networks or platforms. Once a user interacts with the site, the crypto drainer scans for active wallet connections and prompts fake authorization requests that, when approved, grant the attacker full access to transfer funds without further consent. Even users who disconnect their wallets after a failed transaction may still fall victim if they previously approved any permissions during their visit.
This domain was flagged by PhishDestroy with a high-risk assessment, supported by concrete technical indicators. VirusTotal analysis shows that only 1 out of 95 security vendors detected malicious activity at the time of evaluation, indicating the sophistication of the threat actor in evading detection. The domain resolves to IP address 188.114.97.3 and is registered through HOSTINGER operations, UAB, a legitimate registrar that has been misused for this campaign. Notably, rizzmas-migrate.lol was created on May 29, 2026, making it a very recent addition to the threat landscape, which often correlates with higher success rates for attackers due to the lack of historical reputation data. The domain also appears on one active security blocklist, further confirming its malicious nature. The use of Cloudflare nameservers (aryanna.ns.cloudflare.com and chad.ns.cloudflare.com) is a common tactic among threat actors to obscure their true infrastructure and evade takedown efforts.
If you visited rizzmas-migrate.lol, take immediate action to secure your cryptocurrency assets. Disconnect all wallets from the site and revoke any unauthorized permissions through your wallet provider’s official interface or tools like Etherscan’s token approval checker for Ethereum-based wallets. Scan your device for malware using reputable antivirus software, as the site may have deployed additional payloads. Report the domain to your wallet provider and consider transferring remaining funds to a new, secure wallet. Avoid interacting with similar domains promising migration services, especially those with recent creation dates or low detection rates on VirusTotal. Stay vigilant and prioritize verified, official platforms for all blockchain-related operations.
Informazioni sulla sicurezza di rete
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DNS4EU | rizzmas-migrate.lol |
malicious | Sinkholed |
| Hagezi Threat Feed | rizzmas-migrate.lol |
malicious | Sinkholed |
Pipeline di risposta alle minacce
Stato della lista di blocco pubblica
Acquisizione salvata
Analisi dei domini
Dettagli tecniciDNS, SAN SSL, timestamp
ICANN OVERSIGHT
Accreditamento e contesto RAA
Accreditamento e contesto RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Analisi di VirusTotal
Dati e relazioni esterne
PD-20260624-121399 Recipient: abuse@hostinger.com Questo sito ti ha influenzato in qualche modo?
Se hai inserito credenziali dell'account, informazioni personali o di pagamento oppure hai scaricato un file da questo dominio, agisci immediatamente. Di seguito sono riportate le risorse per aiutarti a segnalare l'incidente e proteggerti.
Segnalalo alle autorità locali
Seleziona il tuo Paese per ottenere contatti ufficiali del crimine informatico o creare una bozza di reclamo →.
Verifica qualsiasi dominio
Analisi delle minacce utilizzando blocklist archiviate, WHOIS, DNS e prove di scansione pubblica
Scansiona oraSegnala un tentativo di phishing
Segnala i domini sospetti al nostro database delle minacce — proteggi la comunità
SegnalaFeed in tempo reale sulle minacce
Segnalazioni recenti di phishing e modifiche osservate della disponibilità
MonitoraRimani informato, rimani al sicuro
Controlla le minacce in tempo reale oppure contesta questa segnalazione se ritieni che si tratti di un falso positivo