1756402135[.]zrmvdefi[.]top
1756402135.zrmvdefi.top — 콘텐츠를 사용할 수 없음. 사기 유형: Crypto Scam. 증거 요약: VirusTotal 2/93 (Gridinsoft, Trustwave); PhishDestroy score 56/100.
원본 포렌식 기록을 보존하기 위해 아래의 상세 PhishDestroy AI 분석은 영어로 유지됩니다.
This investigation documents the infrastructure associated with 1756402135.zrmvdefi.top, a domain classified as a crypto drainer. The domain was registered on February 21, 2026 and resolves to the IPv4 address 3.167.152.31, which is allocated to Amazon.com, Inc. (AS16509) and geolocated to the United States. VirusTotal analysis records two positive detections out of ninety‑three scanned security engines, indicating limited but non‑trivial recognition by threat‑intelligence services.
The site has been added to at least one public security blocklist and is actively blocked by the PhishDestroy filtering platform. TLS inspection reports a certificate labeled “WE1”, suggesting a publicly issued SSL certificate without further validation details. Current network scans show the host is offline, and no HTTP response was observed at the time of assessment, limiting real‑time behavioral observation.
The available evidence confirms the domain’s role in a cryptocurrency‑draining campaign, yet the specific payload delivery mechanisms, victim targeting patterns, and command‑and‑control endpoints remain unverified. Defensive operators should continue to block the domain at DNS and proxy layers, monitor outbound traffic to the associated Amazon IP range for anomalous connections, and incorporate the two VirusTotal detections into existing indicator‑of‑compromise (IoC) feeds. Ongoing threat‑intel correlation is advised to capture any re‑activation attempts or related infrastructure sharing.
위협 대응 Pipeline
공개 차단 목록 상태
저장된 캡처
도메인 인텔리전스
기술적 세부 사항DNS, SSL SAN, 타임스탬프
VirusTotal 분석
증거 및 외부 보고서
이 사이트로 인해 영향을 받으셨나요?
계정 자격 증명, 개인 정보 또는 결제 정보를 입력했거나 이 도메인에서 파일을 다운로드한 경우 즉시 조치를 취하세요. 다음은 사건을 신고하고 자신을 보호하는 데 도움이 되는 리소스입니다.
지역 당국에 신고하십시오
공식 사이버 범죄 연락처 또는 불만사항 초안 작성 →를 받으려면 국가를 선택하세요.