추적 대상 도메인을 검색하고, 저장된 증거, 탐지 내역 및 최근 확인된 가용성 정보를 검토합니다.
How This Attack Works
Ice Phishing is a sophisticated technique that targets users by manipulating blockchain transactions. Here's how it typically unfolds.
STEP 1
Target Identification
Attackers identify potential victims, often targeting users with significant cryptocurrency holdings.
STEP 2
Setup Spoofed Environment
The attacker creates a fake website or app mimicking a legitimate service to deceive users.
STEP 3
Credential Harvesting
Users are tricked into entering sensitive information, allowing attackers to gain access to their accounts.
STEP 4
Unauthorized Transactions
With access to the victim's account, attackers execute unauthorized transactions, siphoning funds.
Technical Analysis
Ice Phishing attacks often involve the use of malicious smart contracts that exploit users by redirecting transactions to the attacker's wallet. Attackers employ social engineering techniques to lure victims into signing transactions that they believe are legitimate. These transactions often use clever code obfuscation to hide the true nature of the transaction. Attackers also leverage compromised infrastructure, such as DNS servers or hosting services like those registered through arin or Vercel Inc., to create convincing phishing environments. By mimicking legitimate services, these attacks bypass traditional security checks, making detection challenging.
Real Cases
Ethereum Wallet Scam (2023)
$1.2 million stolen
Attackers used a fake wallet service to steal credentials, resulting in a substantial loss of Ethereum funds.
Crypto Exchange Phishing (2024)
$2.5 million stolen
A phishing site mimicking a popular exchange tricked users into entering their login details, leading to significant asset theft.
DeFi 플랫폼 Breach (2024)
$3.8 million stolen
A decentralized finance platform was targeted by ice phishers who exploited smart contract vulnerabilities to siphon funds.
How to Detect
Unusual domain names that closely resemble legitimate services
Unexpected requests for private keys or seed phrases
Emails or messages urging immediate action on your crypto assets
Anomalies in transaction requests, such as unexpected gas fees
Lack of HTTPS encryption on websites requiring sensitive input
How to Protect Yourself
1
Always verify the URL before entering sensitive information
2
Enable two-factor authentication on all accounts
3
Regularly monitor transaction logs for unauthorized activities
4
Educate yourself about common phishing tactics
5
Use hardware wallets for enhanced security
Frequently Asked Questions
Data sourced from PhishDestroy threat intelligence database — 40 domains tracked for this threat type
Ice Phishing 40 domains
![[스크린샷] rectification-fixuserauthentication.vercel.app](https://screenshots.phishdestroy.io/019b7ed1-9c05-724f-be26-6779e7bbf713.png)
rectification-fixuserauthentication.vercel.app
![[스크린샷] rectifyissues-now.vercel.app](https://screenshots.phishdestroy.io/019ad9dc-a8f9-7496-9f58-4063393adb2b.png)
rectifyissues-now.vercel.app
![[스크린샷] supports-rectification.vercel.app](https://screenshots.phishdestroy.io/019a9c76-1932-74db-9217-8f8de2c6b7a2.png)
supports-rectification.vercel.app
![[스크린샷] authwalletconnect.com](https://screenshots.phishdestroy.io/019a55dd-1538-71a1-8f41-3c8fd3c10b6c.png)
authwalletconnect.com
![[스크린샷] flaretokensdrop.com](https://screenshots.phishdestroy.io/019a0ba7-0513-73a8-85ff-377fdcfa6601.png)
flaretokensdrop.com
![[스크린샷] seaportal.fo](https://screenshots.phishdestroy.io/019b2769-2255-7616-97b5-416af1d16013.png)
seaportal.fo
![[스크린샷] agencyanalyticsframe.us.com](https://screenshots.phishdestroy.io/019a6ba2-bbea-745d-8192-3abe1976a30f.png)
agencyanalyticsframe.us.com
![[스크린샷] enacoin-newbridge.com](https://screenshots.phishdestroy.io/01988f99-6ec9-7749-a251-4ba878f352e4.png)
enacoin-newbridge.com
![[스크린샷] flrconnectportal.live](https://screenshots.phishdestroy.io/0198f6f7-e587-74fa-b21e-4ed7da3ca11b.png)
flrconnectportal.live
![[스크린샷] airdrop.wrlomhole.net](https://screenshots.phishdestroy.io/48f8afd2-8cd6-481c-a85b-a813c360725f.png)
airdrop.wrlomhole.net
![[스크린샷] aoerodrome.finance](https://screenshots.phishdestroy.io/0198861c-2832-731e-9183-12249f2e95af.png)
aoerodrome.finance
![[스크린샷] chainxtrade.com](https://screenshots.phishdestroy.io/019a0b9b-a97d-718e-a801-6b4d5c8b90bb.png)
chainxtrade.com
![[스크린샷] ethdrawclaimdrop.org](https://screenshots.phishdestroy.io/019a53fc-b9ab-77ed-800a-4d2bb3f818c6.png)
ethdrawclaimdrop.org
![[스크린샷] test123.sphere-drainer.cc](https://screenshots.phishdestroy.io/0198e733-e3df-70fa-9f7f-9f68f9290422.png)
test123.sphere-drainer.cc
![[스크린샷] arb.claimscrypto.top](https://screenshots.phishdestroy.io/a62abc9a-75d6-4149-9991-a2d18270df12.png)
arb.claimscrypto.top
![[스크린샷] eth-drainer.exontra.com](https://screenshots.phishdestroy.io/019a4e60-16d4-743c-a2ee-5255aa347b44.png)
eth-drainer.exontra.com
![[스크린샷] drnr.fiznen.com](https://screenshots.phishdestroy.io/019a05d1-d001-77e9-88e5-11f060a53df1.png)
drnr.fiznen.com
![[스크린샷] h2-finance.web.app](https://screenshots.phishdestroy.io/01966436-59fe-718e-8052-4aeb2cb8f054.png)
h2-finance.web.app
![[스크린샷] xrpdistributions.firebaseapp.com](https://screenshots.phishdestroy.io/0198e9fa-ba03-723e-8d86-57ee6aaba4cd.png)
xrpdistributions.firebaseapp.com
![[스크린샷] ngcrp.com](https://screenshots.phishdestroy.io/01996024-e383-7749-b654-6fa823fa9158.png)
ngcrp.com
![[스크린샷] bitrane.com](https://screenshots.phishdestroy.io/0198b032-b4dc-704b-8fb9-1165fae5cd48.png)
bitrane.com
![[스크린샷] drainer.bexcapitaltrade.com](https://screenshots.phishdestroy.io/0199dd20-911d-75c0-89f1-eee848542dbe.png)
drainer.bexcapitaltrade.com
![[스크린샷] flare.linkportalnet.com](https://screenshots.phishdestroy.io/01991000-3ea7-7124-8143-f20b9167f065.png)
flare.linkportalnet.com
![[스크린샷] lumiachain.com](https://screenshots.phishdestroy.io/019891bd-1be2-7200-83ee-8ee5548c0b28.png)
lumiachain.com
![[스크린샷] trovako.com](https://screenshots.phishdestroy.io/019a192a-93bc-7498-9b56-169fc17d6c79.png)
trovako.com
![[스크린샷] arbitriums.icu](https://screenshots.phishdestroy.io/2aa58a39-71c5-452a-909d-031a195b6314.png)
arbitriums.icu
![[스크린샷] xrpdistributions.web.app](https://screenshots.phishdestroy.io/0199104c-5775-779e-b975-ef3d336a7094.png)
xrpdistributions.web.app
![[스크린샷] ledgerlane.icu](https://screenshots.phishdestroy.io/01993aee-5153-72d2-a50f-4405e190ced5.png)
ledgerlane.icu
![[스크린샷] megaethlabs.top](https://screenshots.phishdestroy.io/019a26b1-52e6-728c-82ab-b1b7f36ea921.png)
megaethlabs.top
![[스크린샷] semantic.nexus-innovators.site](https://screenshots.phishdestroy.io/0199e67b-dc5e-7492-9d2d-d4fd9d5ec959.png)
semantic.nexus-innovators.site
![[스크린샷] www.amlcheckvault.com](https://screenshots.phishdestroy.io/0199c614-3ef3-75ba-9c24-1557916ce301.png)
www.amlcheckvault.com
![[스크린샷] claim.mindof-pepe.world](https://screenshots.phishdestroy.io/01993d3f-9922-7478-af19-b673d85e895d.png)
claim.mindof-pepe.world
![[스크린샷] defi-launch.io](https://screenshots.phishdestroy.io/80dfb7f3-6132-4416-bbae-3df5f626fa91.png)
defi-launch.io
![[스크린샷] metaversentf.com](https://screenshots.phishdestroy.io/2a9703da-98d8-402e-9fda-1b21e5a341f5.png)
metaversentf.com
![[스크린샷] bridge.maob.site](https://screenshots.phishdestroy.io/50d9f957-4d7f-4e42-902f-b9588eaa2459.png)
bridge.maob.site
![[스크린샷] dymensionrollapps.com](https://screenshots.phishdestroy.io/40c55222-2a7e-4ca7-a93a-11cc1e5eccb4.png)
dymensionrollapps.com
![[스크린샷] fincaptor.app](https://screenshots.phishdestroy.io/45aede2b-b9c6-4951-8682-96e9c1da6352.png)
fincaptor.app
![[스크린샷] publicsale.well3.website](https://screenshots.phishdestroy.io/169d0980-eda0-46c3-a1f1-b6d473b6514d.png)
publicsale.well3.website
![[스크린샷] randombitcoins.com](https://screenshots.phishdestroy.io/627ae12e-ffe5-4e50-a5a6-e45184c5825e.png)
randombitcoins.com
위협 대응 Pipeline
이 허브에 포함된 모든 도메인이 어떻게 검증되며, 확인된 위협은 어떻게 무력화되는지. 전체 파이프라인 시각화 →
위협 인텔리전스 점검— 모든 도메인은 다음 항목에 대해 스캔 및 교차 확인을 거칩니다:
urlscan.io스크린샷 · DOM · HTTPVirusTotal90+ AV enginesGoogle Safe BrowsingTransparency 보고서Cloudflare RadarDNS · certs · categoriesAlienVault OTXThreat-intel pulses웨이백 머신Historical evidenceabuse.ch ThreatFoxIOC correlationcrt.shCertificate TransparencyDNS 보안 FiltersQuad9 · AdGuard · CleanBrowsingWeb-확인Full surface scan
글로벌 공급업체 동기화— 확인된 탐지 결과는 29개 파트너사에 전송됩니다:
GoogleSafe BrowsingGoogleWeb Risk APIMicrosoftSmartScreenVirusTotalDetection feedCloudflareRadar / 1.1.1.1YandexSafe BrowsingURLScan.ioPublic scanESETWebGuard비트디펜더Threat exchangeNortonSafe WebSymantec사이트 리뷰AviraCloud detectionAvast / AVGWeb Shield카스퍼스키OpenTIPDr.WebOnline scanner넷크래프트제거 APIPhishTankVerified voteAPWG eCXBulk feedPhishStatsOpen feedPhish.보고서Hosting abuseSpamhausDBL feedPolySwarmMarketplaceCheckPhishBolster scanQutteraMalware scanURLquerySandboxCriminal IPAsset intelCRDFThreat CenterScamadviserTrust scoreMyWOTWeb of Trust