MALICIOUS — HIGH
wtfgyms[.]com
The domain www.wtfgyms.com was an active brand-impersonation phishing site targeting users of the cryptocurrency platform 'near'.
- VirusTotal
- 2/91
- Blocklists
- No stored match
- 가용성
- 마지막으로 알려진 활성 · HTTP 200
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
wtfgyms.com — 마지막으로 알려진 활성 (HTTP 200). 브랜드 사칭: Near; 사기 유형: Brand Impersonation. 증거 요약: VirusTotal 2/91 (alphaMountain.ai, Gridinsoft); PhishDestroy score 66/100. 등록기관: GoDaddy.
원본 포렌식 기록을 보존하기 위해 아래의 상세 PhishDestroy AI 분석은 영어로 유지됩니다.
Evidence Analysis
The domain www.wtfgyms.com was an active brand-impersonation phishing site targeting users of the cryptocurrency platform 'near'. It posed as a legitimate fitness service to harvest login credentials or personal information, not a crypto drainer. As of the latest verification, www.wtfgyms.com has been taken offline.
Technical indicators show limited but clear malicious signals: 1 of 95 VirusTotal security vendors flagged the domain. The site was registered through GoDaddy.com, LLC on February 6, 2024, and resolved to IP address 65.0.171.184, hosted on Amazon’s infrastructure in India. It appeared on 1 security blocklist (PhishDestroy) and was referenced in 1 AlienVault OTX threat intelligence pulse. The SSL certificate was issued by Amazon RSA 2048 M04, and the observed page title was 'Get the Best Fitness Workouts, Gyms and membership in India | WTF'. Gridinsoft assigned a trust score of 0 out of 100, and technologies detected included Node.js, React, Next.js, Google Tag Manager, Google Analytics, Facebook Pixel, and Webpack.
Users who interacted with www.wtfgyms.com should immediately change any passwords entered on the site, enable two-factor authentication on all accounts, and monitor for unauthorized access or fraudulent transactions. Report the phishing domain to Google Safe Browsing, the Anti-Phishing Working Group at reportphishing@apwg.org, and the impersonated brand’s security team. If financial or cryptocurrency accounts were accessed, contact the platform’s support for further investigation.
데이터 적용 범위12 recorded checks
위협 대응 Pipeline
공개 차단 목록 상태
저장된 캡처
도메인 인텔리전스
기술적 세부 사항DNS, SSL SAN, 타임스탬프
ICANN OVERSIGHT
인증 및 RAA 상황
인증 및 RAA 상황
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
사용 기술 · 7 identified
Node.js is an open-source, cross-platform, JavaScript runtime environment that executes JavaScript code outside a web browser.
nodejs.org 신뢰도 100%React is an open-source JavaScript library for building user interfaces or UI components.
reactjs.org 신뢰도 100%Next.js is a React framework for developing single page Javascript applications.
nextjs.org 신뢰도 100%Google Tag Manager is a tag management system (TMS) that allows you to quickly and easily update measurement codes and related code fragments collectively known as tags on your website or mobile app.
www.google.com 신뢰도 100%Google Analytics is a free web analytics service that tracks and reports website traffic.
google.com 신뢰도 100%Facebook pixel is an analytics tool that allows you to measure the effectiveness of your advertising.
facebook.com 신뢰도 100%VirusTotal 분석
보관된 증거
사이트 성능 분석
Google PageSpeed Insights — mobile performance audit of wtfgyms.com · checked Mar 2, 2026
증거 및 외부 보고서Independent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
계정 자격 증명, 개인 정보 또는 결제 정보를 입력했거나 이 도메인에서 파일을 다운로드한 경우 즉시 조치를 취하세요. 다음은 사건을 신고하고 자신을 보호하는 데 도움이 되는 리소스입니다.
지역 당국에 신고하십시오
공식 사이버 범죄 연락처 또는 불만사항 초안 작성 →를 받으려면 국가를 선택하세요.