root-xyz-isme-claim[.]pages[.]dev
“Root Protocol | Building the Operating System of Web3”
root-xyz-isme-claim.pages.dev — 확인되지 않음. 브랜드 사칭: Google; 사기 유형: Brand Impersonation. 증거 요약: VirusTotal 2/91 (alphaMountain.ai, Gridinsoft); URLQuery 2 alerts; 1 external blocklist match (ScamSniffer); PhishDestroy score 76/100. 등록기관: Cloudflare.
원본 포렌식 기록을 보존하기 위해 아래의 상세 PhishDestroy AI 분석은 영어로 유지됩니다.
PhishDestroy identifies root-xyz-isme-claim.pages.dev as an ACTIVE crypto_drainer campaign operating at HIGH risk, with unique seed c9f510. This fraudulent page impersonates Root Protocol’s “Building the Operating System of Web3” branding to deceive users into connecting cryptocurrency wallets and authorizing malicious transactions. The threat actor leverages Cloudflare Pages and Google Trust Services SSL to appear legitimate, while quietly draining funds from exposed wallets.
This domain was flagged by 2 out of 95 VirusTotal security vendors, appears on 1 known blocklist (ScamSniffer), and resolves to IP 188.114.96.3 via Cloudflare, Inc. The SSL certificate issued by Google Trust Services (a tactic to bypass security filters) adds superficial trustworthiness. Despite its polished appearance, the underlying infrastructure and detection gaps reveal a sophisticated operation designed to harvest private keys, seed phrases, and authorize unauthorized blockchain transactions.
To mitigate risk, users must immediately avoid interacting with root-xyz-isme-claim.pages.dev or any derivative pages under the same seed c9f510. Never connect wallets or enter recovery phrases on unfamiliar sites—especially those claiming to be “Root Protocol” or “Web3 OS.” Enable wallet filters like ScamSniffer, revoke any unauthorized smart contract approvals via tools like Revoke.cash, and report suspicious domains to threat intelligence platforms. Stay vigilant: crypto drainers exploit urgency and branding trust to steal assets irreversibly.
네트워크 보안 인텔리전스
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Private YARA rules | root-xyz-isme-claim.pages.dev/892e12242a26e9d_0eb9b3f1f311fa.js |
audit | Hunting_JS_WebAssembly |
| DNS4EU | root-xyz-isme-claim.pages.dev |
malicious | Sinkholed |
위협 대응 Pipeline
공개 차단 목록 상태
사용 기술 · 3 identified
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
Web infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
VirusTotal 분석
증거 및 외부 보고서
“@goyxard Telegram Username”
이 사이트로 인해 영향을 받으셨나요?
계정 자격 증명, 개인 정보 또는 결제 정보를 입력했거나 이 도메인에서 파일을 다운로드한 경우 즉시 조치를 취하세요. 다음은 사건을 신고하고 자신을 보호하는 데 도움이 되는 리소스입니다.
지역 당국에 신고하십시오
공식 사이버 범죄 연락처 또는 불만사항 초안 작성 →를 받으려면 국가를 선택하세요.