MALICIOUS — CRITICAL
echo-dapp-crypto-big[.]pages[.]dev
Security analysis of echo-dapp-crypto-big.pages.dev covers observed phishing indicators, infrastructure evidence, current status, and defensive guidance.
- VirusTotal
- 1/91
- Blocklists
- 2 · MetaMask, SEAL
- 可用性
- 最後に確認されたアクティブな状態 · HTTP 200
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
echo-dapp-crypto-big.pages.dev — 最後に確認されたアクティブな状態 (HTTP 200). 証拠の概要: VirusTotal 1/91 (Forcepoint ThreatSeeker); 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 83/100. レジストラ: Cloudflare Pages.
元のフォレンジック記録を保持するため、下の PhishDestroy AI 詳細分析は英語のままです。
Evidence Analysis
This domain, echo-dapp-crypto-big.pages.dev, is actively flagged as a high-risk phishing site targeting users of the BingX cryptocurrency exchange, as indicated by its page title and confirmed by multiple security blocklists. Analysis reveals the domain is hosted on Cloudflare Pages infrastructure, resolving to IP 188.114.96.3, which is geolocated to Canada under Cloudflare, Inc. The SSL certificate is issued by Let's Encrypt (serial YE2), a common choice for both legitimate and malicious sites. The domain is currently live, returning an HTTP 200 status, and has been blocked by security vendors including PhishDestroy, MetaMask, and SEAL, as well as appearing on three independent blocklists. No vendor detections were recorded in the most recent VirusTotal scan, though this absence does not confirm safety, particularly given the domain's active status and prior blocklist listings. The use of Cloudflare Pages, a legitimate development platform, may complicate takedown efforts due to its shared hosting model. Defenders should treat this domain as an active threat to BingX users, particularly those interacting with decentralized applications or crypto-related services. Immediate action is recommended, including blocking the domain at the DNS or proxy level, alerting security teams to monitor for related indicators, and reviewing logs for connections to the IP 188.114.96.3. Further investigation into the site's exact functionality—such as whether it harvests credentials, distributes malware, or operates as a crypto drainer—is warranted, though no concrete evidence of these behaviors is currently available in the provided data.
データの網羅性12 recorded checks
脅威対応 Pipeline
公開ブロックリスト登録状況
ドメイン・インテリジェンス
技術的な詳細DNS、SSL SAN、タイムスタンプ
VirusTotalによる分析
証拠および外部報告書Independent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
アカウント資格情報、個人情報、支払い情報を入力した場合、またはこのドメインからファイルをダウンロードした場合は、すぐに対処してください。インシデントを報告し、自分自身を守るのに役立つリソースを以下に示します。
お住まいの地域の当局へ報告してください
サイバー犯罪の公式連絡先 または 苦情草稿を作成する → を取得するには、国を選択してください。