sso-en-nndax[.]webflow[.]io
“NDAX® | Login - sign in on Strikingly”
sso-en-nndax.webflow.io — Contenuto non disponibile. Simulazione del marchio: Genericcrypto; Tipo di truffa: Credential Phishing. Riepilogo delle prove: VirusTotal 19/91 (alphaMountain.ai, BitDefender, Chong Lua Dao, CyRadar, Ermes); URLScan malicious verdict; CF Radar malicious; PhishDestroy score 95/100. Registrar: Webflow.
L’analisi dettagliata di PhishDestroy AI resta in inglese per preservare il rapporto forense originale.
This domain, sso-en-nndax.webflow.io, operates as a credential theft campaign impersonating the NDAX cryptocurrency exchange platform. Analysis indicates the site presents a fraudulent login interface mimicking the legitimate NDAX authentication portal, designed to harvest user credentials, including usernames, passwords, and potentially multi-factor authentication codes. The inclusion of the NDAX brand name in the page title (NDAX® | Login - sign in on Strikingly) and the use of Webflow’s hosting infrastructure suggest an attempt to exploit the trust associated with both the cryptocurrency exchange and the web development platform. Such campaigns are commonly leveraged to gain unauthorized access to user accounts, enabling subsequent financial theft or further exploitation of compromised credentials across other platforms.
Infrastructure analysis reveals the domain is hosted on Webflow’s platform, as indicated by its registration through the service and resolution to the IP address 172.64.151.8, which is associated with Cloudflare’s network. The domain is flagged by 19 out of 95 security vendors on VirusTotal, indicating a moderate level of detection but sufficient concern to warrant blocking. The SSL certificate is issued by Google Trust Services, a legitimate provider, which may contribute to the domain’s appearance of authenticity. Technologies detected include Webflow for hosting, Cloudflare for content delivery, and HTTP/3 for enhanced performance, all of which are consistent with modern web infrastructure but do not mitigate the malicious intent of the domain.
Users who have visited this domain or entered credentials into the fraudulent login interface should immediately take corrective action. First, reset passwords for the legitimate NDAX platform and any other services where the same credentials may have been reused. Enable multi-factor authentication on all critical accounts to mitigate the risk of unauthorized access. Monitor financial and cryptocurrency accounts for suspicious activity, and report any unauthorized transactions to the relevant platform. Additionally, consider scanning local devices for malware, as credential theft campaigns may be accompanied by secondary payloads designed to maintain persistence or exfiltrate additional data.
Informazioni sulla sicurezza di rete
Pipeline di risposta alle minacce
Stato della lista di blocco pubblica
Tecnologie · 3 identified
Webflow is Software-as-a-Service (SaaS) for website building and hosting.
webflow.com Confidenza al 100%Cloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com Confidenza al 100%HTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org Confidenza al 100%Analisi di VirusTotal
Analisi delle prestazioni del sito
Google PageSpeed Insights — mobile performance audit of sso-en-nndax.webflow.io · checked Jul 5, 2026
Dati e relazioni esterne
Questo sito ti ha influenzato in qualche modo?
Se hai inserito credenziali dell'account, informazioni personali o di pagamento oppure hai scaricato un file da questo dominio, agisci immediatamente. Di seguito sono riportate le risorse per aiutarti a segnalare l'incidente e proteggerti.
Segnalalo alle autorità locali
Seleziona il tuo Paese per ottenere contatti ufficiali del crimine informatico o creare una bozza di reclamo →.
Verifica qualsiasi dominio
Analisi delle minacce utilizzando blocklist archiviate, WHOIS, DNS e prove di scansione pubblica
Scansiona oraSegnala un tentativo di phishing
Segnala i domini sospetti al nostro database delle minacce — proteggi la comunità
SegnalaFeed in tempo reale sulle minacce
Segnalazioni recenti di phishing e modifiche osservate della disponibilità
MonitoraRimani informato, rimani al sicuro
Controlla le minacce in tempo reale oppure contesta questa segnalazione se ritieni che si tratti di un falso positivo