pub-e2f6341451ca4b26ac23c6bea7b95d1d[.]r2[.]dev
“MetaMask”
pub-e2f6341451ca4b26ac23c6bea7b95d1d.r2.dev — 콘텐츠를 사용할 수 없음. 브랜드 사칭: Genericemail; 사기 유형: Crypto Drainer. 증거 요약: VirusTotal 16/94 (ADMINUSLabs, alphaMountain.ai, BitDefender, Chong Lua Dao, CyRadar); URLQuery 4 alerts; URLScan malicious verdict; PhishDestroy score 95/100. 등록기관: Cloudflare R2.
원본 포렌식 기록을 보존하기 위해 아래의 상세 PhishDestroy AI 분석은 영어로 유지됩니다.
PhishDestroy identifies pub-e2f6341451ca4b26ac23c6bea7b95d1d.r2.dev as a high-risk crypto drainer phishing domain actively stealing cryptocurrency through deceptive wallet connection prompts. This domain employs advanced impersonation techniques to trick users into authorizing malicious transactions that drain funds directly from wallets. The threat is particularly dangerous as it leverages legitimate-looking interfaces to bypass standard security protocols, making it difficult for average users to detect without specialized tools. This domain resolves to IP address 104.18.50.34 and operates under a Let's Encrypt SSL certificate to appear trustworthy. PhishDestroy's analysis reveals that 16 out of 95 security vendors on VirusTotal flag this domain, indicating significant malicious activity. The domain appears on three major blocklists including PhishingArmy, PhishingDB, and OISD, demonstrating consistent identification as a malicious resource across multiple security platforms. While the exact creation date isn't provided in available intelligence, these multiple independent detections strongly suggest this is not a newly emerged threat but rather an established malicious domain operating with sophisticated evasion techniques. The combination of high VT detection rate, multiple blocklist inclusions, and active crypto drainer functionality places this domain at maximum risk level for cryptocurrency users. Users should immediately cease any interaction with this domain and verify the safety of similar domains using PhishDestroy's specialized scanning tools. For crypto drainer threats specifically, users should always verify website authenticity through blockchain transaction simulators before authorizing any wallet connections. This domain should be added to all personal and organizational blocklists, and any cryptocurrency transactions involving this domain should be reported to relevant authorities. Organizations should implement network-level blocking of both the domain and its resolving IP address (104.18.50.34) to prevent accidental exposure through employee devices or automated systems. The crypto drainer nature of this threat requires immediate action as funds lost through such attacks are typically unrecoverable due to blockchain immutability.
네트워크 보안 인텔리전스
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Cloudflare DNS | pub-e2f6341451ca4b26ac23c6bea7b95d1d.r2.dev |
malicious | Sinkholed |
| OpenDNS | pub-e2f6341451ca4b26ac23c6bea7b95d1d.r2.dev |
phishing | Phishing Block |
| Quad9 DNS | pub-e2f6341451ca4b26ac23c6bea7b95d1d.r2.dev |
malicious | Sinkholed |
| DNS4EU | pub-e2f6341451ca4b26ac23c6bea7b95d1d.r2.dev |
malicious | Sinkholed |
위협 대응 Pipeline
공개 차단 목록 상태
VirusTotal 분석
사이트 성능 분석
Google PageSpeed Insights — mobile performance audit of pub-e2f6341451ca4b26ac23c6bea7b95d1d.r2.dev · checked Apr 22, 2026
증거 및 외부 보고서
이 사이트로 인해 영향을 받으셨나요?
계정 자격 증명, 개인 정보 또는 결제 정보를 입력했거나 이 도메인에서 파일을 다운로드한 경우 즉시 조치를 취하세요. 다음은 사건을 신고하고 자신을 보호하는 데 도움이 되는 리소스입니다.
지역 당국에 신고하십시오
공식 사이버 범죄 연락처 또는 불만사항 초안 작성 →를 받으려면 국가를 선택하세요.