1musk[.]co
“Trump x Musk — Official BTC, ETH & DOGE Giveaway!”
1musk.co — Não verificado. Tipo de golpe: Fake Airdrop. Resumo das evidências: VirusTotal 5/91 (alphaMountain.ai, Forcepoint ThreatSeeker, Fortinet, Gridinsoft, SOCRadar); PhishDestroy score 71/100. Registrador: Dynadot.
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
1musk.co is an active malicious site observed on July 12, 2026 that leverages a fabricated giveaway narrative involving former President Trump and entrepreneur Elon Musk. The landing page advertises a “Trump x Musk — Official BTC, ETH & DOGE Giveaway!” and attempts to lure victims into submitting cryptocurrency wallet credentials. The site returns HTTP 200 and presents a valid Let’s Encrypt certificate (E8), indicating the operators have obtained a standard TLS certificate to increase perceived legitimacy. The domain was registered on February 21, 2026 through Dynadot LLC and resolves to the IPv4 address 5.189.161.88, which is hosted in France under ASN 51167 belonging to Contabo GmbH. Authoritative name servers are ns1.dyna-ns.net and ns2.dyna-ns.net, both typical of Dynadot‑managed domains. The hosting provider and the use of a free certificate are common tactics for rapidly deployed phishing infrastructure. Reputation services flag the site as high‑risk. Gridinsoft assigns a trust score of 0 out of 100, and VirusTotal reports that 2 of 95 scanned security vendors flag the domain as malicious. The domain appears on one external blocklist and is already listed by the PhishDestroy sink‑hole, confirming active mitigation by at least one security community. The combination of a fresh registration, low trust score, and limited but positive detection across vendors supports the high‑risk classification. Defenders should block 1musk.co at perimeter and DNS layers, and add the IP address 5.189.161.88 to any network‑level deny lists. Continuous monitoring of the associated name servers and the ASN can reveal additional infrastructure reused in future campaigns. End‑user awareness messaging should highlight the fake giveaway lure and advise against providing cryptocurrency wallet information to unsolicited sites. Incident response teams should treat any compromise related to this domain as a credential‑theft event and initiate standard containment and forensic procedures.
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Análise do VirusTotal
Evidências e relatórios externos
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo