⚠️
このドメインは悪意のあるものとして報告されています
Detected by 1 security vendor and listed in 1 public blocklist. Exercise extreme caution — do not enter credentials or personal information. Create a complaint draft from this stored evidence, review it, and submit it yourself to the appropriate authority.
Domain security & threat intelligence

nodesrefresh[.]com

nodesrefresh.com のフィッシング・安全性チェック

“WalletConnect”

Threat verdict High 58/100 stored risk score
Availability Content unavailable Content was unavailable in the latest observation
Risk signals
VirusTotal: 1/95 detections 1 stored blocklist match Brand impersonation: WalletConnect
1/95 VT Nov 14, 2025 Unavailable since Feb 23, 2026 1 Blocklist WalletConnect Generic Phishing 101d to unavailable UA UA + more
レポート概要

nodesrefresh.com:VirusTotal の 95 エンジン中 1 件が検出。DNS、SSL、レジストラ、ブロックリスト、脅威情報を確認できます。

元のフォレンジック記録を保持するため、下の PhishDestroy AI 詳細分析は英語のままです。

Evidence Summary
HIGH
Ref
38D2F893
Score
58/100
Mode
Evidence v1

PhishDestroy first recorded nodesrefresh.com on Nov 14, 2025. This English evidence brief is rebuilt from the current structured observations stored for the report. The current stored risk score is 58/100.

The latest stored availability state is “Content unavailable” on Aug 1, 2026 at 03:12 UTC. This is a reachability snapshot, not proof of the cause of any outage, restriction, or status change.

VirusTotal returned 1 detection from 95 scanners in the stored check on Feb 23, 2026 at 07:42 UTC. The independent blocklist snapshot recorded 1 match (ScamSniffer) across 10 configured external sources on Aug 2, 2026 at 00:20 UTC. PhishDestroy's own listing is excluded from that count.

Other stored evidence. Google Safe Browsing stored no positive flag on Mar 3, 2026 at 05:14 UTC. This time-bound result is not evidence of safety. AlienVault OTX stored 0 pulse references on Mar 1, 2026 at 18:43 UTC. OTX pulses are community-intelligence references, not vendor verdicts. The Spamhaus DBL snapshot stored no positive result on Jul 14, 2026 at 20:32 UTC. That result is not evidence of safety. A URLScan capture is stored from Mar 1, 2026 at 02:17 UTC.

Stored context lists registrar GRANSY S.R.O D/B/A SUBREG.CZ, IP address 185.255.122.10, registration date Oct 25, 2025, apparent target WalletConnect. Except for the registration date, these fields do not share a source timestamp in this report and may change.

Treat these as stored, time-bound observations rather than a live safety guarantee. Source verdicts and reachability can change, and zero or missing vendor matches never prove that a domain is safe. Avoid interacting with the domain while uncertainty remains, and use the appeal process if this report is inaccurate.

VirusTotal
VirusTotal
1 det.
URLScan
URLScan
Gridinsoft
61/100
年齢
9 mo
Observed status
Content unavailable
PhishDestroy
DestroyList
Listed
データの網羅性 VirusTotal 1 / 95 URLQuery checked — no match OTX no pulses CFレーダー clean URLScan capture stored report URLScan verdict checked — no malicious verdict DNSブロック not checked TLS no certificate data WHOIS 9 mo old Screenshot external capture リダイレクトチェーン not probed Gridinsoft 61/100
セキュリティシグナル
GS Gridinsoft Analysis 61 / 100
Hosting SSL Certificate Young Domain

脅威対応 Pipeline

Discovery
Checks
Reports
Availability
14/15
事前発見とデータ取り込み
脅威の検知
1/1 ✓
脅威の検知
nodesrefresh.com 検出され、詳細な分析のためにキューに入れられた
Nov 14, 2025
Threat Intelligence Checks
URLScan.io Capture · URLScan Verdict · Cloudflare Radar · VirusTotal · Google Safe Browsing · Blocklist Detection · Brand Impersonation · Forensic Evidence Collected · Technical Analysis Recorded · Cloudflare Radar Scan
10/10 ✓
URLScan.io Capture
Stored URLScan report with capture artifacts
Mar 01, 2026
URLScan Verdict
URLScan returned no malicious verdict; this provider result is not a safe-domain determination · score 0
Jul 29, 2026
Cloudflare Radar
Scanned via Cloudflare Radar — DNS, certificates & network data
VirusTotal
1 / 95 vendors flagged on VirusTotal
Feb 23, 2026
Google Safe Browsing
Mar 03, 2026
ブロックリストの検出
掲載先 1 blocklist: ScamSniffer
Aug 02, 2026
Brand Impersonation
Impersonation of WalletConnect
Forensic Evidence Collected
Stored evidence from URLScan.io, stored screenshot
Mar 01, 2026
Technical Analysis Recorded
The report contains stored technology or forensic-analysis results
Aug 02, 2026
Cloudflare Radar Scan
Scanned via Cloudflare Radar — network analysis completed
Mar 07, 2026
Notification Records
Complaint Draft Available
PENDING
Complaint Draft Available
No submission is recorded. You can create a draft, review it, and submit it yourself to the appropriate authority.
公開・稼働状況
DestroyList Published · Content Observed Unavailable · Time to First Unavailability
3/3 ✓
DestroyList 公開
Nov 14, 2025
Content Observed Unavailable
The latest stored checks indicate that the reported content is unavailable; this does not establish who or what caused the change
Feb 23, 2026
Time to First Unavailability
2424 hours elapsed from detection to the first unavailable observation

公開ブロックリスト登録状況

証拠の収集

Stored Capture
2025-11-14 02:57 UTC
Malicious · 1/95 engines
Forensic screenshot of nodesrefresh.com showing the phishing page layout
IP: 185.255.122.10
GRANSY S.R.O D/B/A SUBREG.CZ
280d old
Page Title
WalletConnect

ドメイン・インテリジェンス

Domainnodesrefresh.com
URLScan Verdict No malicious verdict recorded score 0 report ↗
Server / ASN nginx/1.24.0 (Ubuntu) · AS30860 YURTEH-AS Virtual Systems LLC, UA
IP Reputation abuse score 0/100 0 reports checked Jun 17, 2026
IP Address 185.255.122.10 UA
GeoUA Kyiv, UA
NetworkASAS30860 · AS30860 Virtual Systems LLC
Registration作成日 Oct 25, 2025 (280d) Expires Oct 25, 2026
Time to First Unavailability 101 days
What we count Elapsed time from the first stored abuse report to the first observation that nodesrefresh.com was unavailable. This does not establish the cause.
What each report contains Stored outgoing report records may reference evidence available at the time, such as vendor verdicts, registration data, hosting details, classifications, or screenshots. This page does not infer the exact payload delivered, receipt, acknowledgement, or action by a recipient.
技術的な詳細DNS、SSL SAN、タイムスタンプ
初確認Nov 14, 2025
Nameserversmars1.freednsdedi.commars2.freednsdedi.com
ICANNの監督 · 手数料徴収済み

ICANNには支払いが済んだ。説明責任は届かなかった。

このgTLDでは、上記のレジストラはICANNとの契約に基づいて運営されています。ICANNは、登録、更新、移管に連動する年間手数料、変動手数料、および取引ベースの手数料を徴収します。

認定:収益化済み。説明責任:後ほどもう一度ご確認ください。

そして魔法が始まります。ICANNがRAA §3.18を書き、レジストラは自らの顧客基盤内の不正利用を自ら調査し、被害者は証拠を無償で提供する一方、各層は誰か別の者が動くのを待ちます。それで被害者が少しでも安全になった気がするなら、結構なことです――請求書は仕事を果たしたわけです。

説明責任についての風刺的なメモ 自動送信は一切行われません。
このドメインを報告する 証拠を提出し、他の人を守る手助けをしましょう

VirusTotalによる分析

1 / 95 security vendors flagged this domain
View on VT
alphaMountain.ai
証拠および外部報告書 Open external tools
Community Scam Report — ChainAbuse
1 report filed for nodesrefresh.com (1 written by a person) · category: Impersonation
“Via a bogus support session via Audius’s Discord channel, a scammer drained all my tokens before my eyes. I connected via Audius Support on Discord. In “Crypto” said I was having an issue. I couldn't retrive 104k Audius tokens that I had unbonded from staking. Was given a “ticket” which I now see was a scam and was shown how to recover and enter my recovery code to fix an RPC issue this is the url I was given: This url: https://nodesrefresh.com/connect.php”
— reported by Anonymous on Nov 7, 2025 · Source: ChainAbuse (TRM Labs) — full report and evidence there.

このサイトによって何か影響を受けましたか?

あなたは一人ではありません。そして、恥じるようなことは何一つありません。 詐欺師たちは、人々の信頼を悪用する手口が巧妙な犯罪者です。被害に遭った経験を報告することは、詐欺に対する最も強力な武器となります。あなたの報告は、他の人が被害に遭うのを防ぎ、法執行機関が対策を講じる助けとなります。 沈黙こそが、詐欺師にとって最大の強みである。 壊して。

If you entered account credentials, personal or payment information, or downloaded a file from this domain, take immediate action. Below are resources to help you report the incident and protect yourself.

復旧を装った詐欺に注意! Criminals may contact victims again while pretending to be investigators, lawyers, or recovery agents. Do not pay upfront fees or share credentials. 回復詐欺について詳しくはこちら →

お住まいの地域の当局へ報告してください

国を選択して、以下の情報を入手してください サイバー犯罪に関する公式の連絡先, or create a complaint draft →

国を選択してください...
180カ国以上
Zero-PII — お客様のデータはブラウザの外に出ることはありません Review and submit it yourself

About This Report: nodesrefresh.com

This report presents the latest stored evidence available to PhishDestroy. Source timestamps are shown where available; availability and vendor verdicts can change after collection.

The site displays a page titled “WalletConnect”, which may be designed to impersonate WalletConnect.

nodesrefresh.com has been flagged by 1 security vendor as of August 1, 2026.

この掲載内容に誤りがあると思われる場合は、以下の手順で 異議申し立てを行う. 当社の調査方法に関する詳細については、当社の よくある質問(FAQ)ページ.

任意のドメインを確認する

Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence

今すぐスキャン

フィッシングを報告する

不審なドメインを当社の脅威データベースに報告してください — コミュニティを守りましょう

Report

リアルタイム脅威情報フィード

Recent phishing reports and observed availability changes

Monitor

最新情報を入手し、安全を確保しましょう

リアルタイムの脅威を監視するか、誤検知だと思われる場合はこのリストに異議を申し立ててください

リアルタイム脅威情報フィード この掲載情報について異議を申し立てる
HTML · IFRAME

このレポートを埋め込む

この脅威情報を、ご自身のウェブサイトやブログで共有してください

embed.html
<iframe
  src="https://phishdestroy.io/ja/embed/domain/nodesrefresh.com"
  title="PhishDestroy threat report for nodesrefresh.com"
  width="100%" height="320"
  loading="lazy"
  referrerpolicy="no-referrer"
  sandbox="allow-same-origin allow-popups allow-popups-to-escape-sandbox"
  style="border:0;border-radius:12px;max-width:100%"
></iframe>

たいへん心のこもった感謝状

風刺的な下書き生成ツール

宛先
手数料の背景

風刺的な下書きです。手数料額は推計であり、このドメインに正確に帰属すると主張するものではありません。