unxc.network
“Web3 Connect Demo”
Notification and current-status evidence
The sent-report ledger records the first outgoing report at .
The recorded recipient is abuse@dynadot.com.
The latest stored availability evidence still shows the domain reachable; 3 months has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
Analysis of the domain unxc.network indicates it is an active credential phishing site targeting Web3 users.
L’analisi dettagliata di PhishDestroy AI resta in inglese per preservare il rapporto forense originale.
Riepilogo delle prove
Analysis of the domain unxc.network indicates it is an active credential phishing site targeting Web3 users. Registered on September 8, 2025, through Dynadot Inc, the domain currently resolves to 104.21.23.22, hosted on infrastructure belonging to Amazon.com, Inc. (AS16509) in the United States. The site employs a 301 HTTP redirect, a common technique to obscure the final phishing destination or evade automated crawlers. SSL encryption is provided by Let's Encrypt (YR1), which, while standard for legitimate sites, is routinely abused by threat actors to lend false credibility. The page title, 'Web3 Connect Demo,' suggests an attempt to mimic legitimate Web3 authentication interfaces, likely aiming to harvest cryptocurrency wallet credentials or private keys. This aligns with the classification of credential phishing, as noted in available threat intelligence. The domain is flagged by four security vendors on VirusTotal and appears on at least one security blocklist, including PhishDestroy. Gridinsoft assigns a trust score of 0/100, further corroborating its malicious status. Infrastructure analysis reveals the use of Cloudflare and HTTP/3, technologies that can enhance performance and resilience but are also leveraged by attackers to mask origin servers and complicate takedown efforts. Nameservers ns1.dyna-ns.net and ns2.dyna-ns.net are associated with the domain, though their historical use in other malicious campaigns is not confirmed in the available data. Defenders should treat unxc.network as an active threat. Network-level blocking of the IP 104.21.23.22 and domain-based filtering are recommended. Given the use of Cloudflare, additional monitoring for related domains or subdomains may be warranted. The exact content and functionality of the phishing page remain unanalyzed, but the combination of technical indicators and threat intelligence confirms its malicious intent. No legitimate use case for this domain has been identified.
Informazioni sulla sicurezza di rete
Forensic History & Detection Timeline
-
Domain Status Transition Sep 16, 2026 · 00:18 UTCDomain state transitioned from dead to alive.
-
Domain Status Transition Sep 15, 2026 · 00:40 UTCDomain state transitioned from alive to dead.
Pipeline di risposta alle minacce
Stato della lista di blocco pubblica
Evasion analysis
Cloaking & traffic-distribution check
Stored crawler-versus-browser observations for this host, plus a live fingerprint check for Keitaro-style traffic distribution systems.
- Stored cloaking flag
- Not observed
- Punteggio di cloaking
- 0/6
- Last cloaking scan
- Server header seen by scanner
Apache
Scanner note: terminal_unconfirmed: candidate_reason=parked; raw=parked; http=200; via=https_proxy; server=Apache
Acquisizione salvata · 4 sources
Analisi dei domini
Dettagli tecniciDNS, SAN SSL, timestamp
ICANN OVERSIGHT
Accreditamento e contesto RAA
Accreditamento e contesto RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Tecnologie · 2 identified
Analisi di VirusTotal
Dati e relazioni esterne
PD-20260618-8CA110 Recipient: abuse@dynadot.com Abuse notice text as sent to the provider
Registrar: Dynadot LLC / Dynadot Inc (United States) Policy Violations: Acceptable Use forbids illegal content; Spam & Abuse Policy prohibits phishing, fraud, malware; Dynadot may disable DNS and suspend domains Applicable Laws: CFAA 18 U.S.C. §1030, Wire Fraud 18 U.S.C. §1343, CAN-SPAM Act
Questo sito ti ha influenzato in qualche modo?
Se hai inserito credenziali dell'account, informazioni personali o di pagamento oppure hai scaricato un file da questo dominio, agisci immediatamente. Di seguito sono riportate le risorse per aiutarti a segnalare l'incidente e proteggerti.
Segnalalo alle autorità locali
Seleziona il tuo Paese per ottenere contatti ufficiali del crimine informatico o creare una bozza di reclamo →.
Verifica qualsiasi dominio
Analisi delle minacce utilizzando blocklist archiviate, WHOIS, DNS e prove di scansione pubblica
Scansiona oraSegnala un tentativo di phishing
Segnala i domini sospetti al nostro database delle minacce — proteggi la comunità
SegnalaFeed in tempo reale sulle minacce
Segnalazioni recenti di phishing e modifiche osservate della disponibilità
MonitoraRimani informato, rimani al sicuro
Controlla le minacce in tempo reale oppure contesta questa segnalazione se ritieni che si tratti di un falso positivo