2ly2ut[.]com
Verificação de phishing e segurança de 2ly2ut.com
“$BOUNTY | Highest USDT Rewards”
2ly2ut.com — Conteúdo indisponível (HTTP 502). Representação da marca: MetaMask; Tipo de golpe: Wallet/seed Phishing. Resumo das evidências: VirusTotal 12/93 (alphaMountain.ai, BitDefender, CRDF, CyRadar, Fortinet); URLQuery 1 alert; Google Safe Browsing flagged; PhishDestroy score 86/100. Registrador: GMO Internet Group.
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
Evidence Analysis
Analysis indicates that the domain 2ly2ut.com was registered on February 21, 2026 through GMO Internet Group, Inc. d/b/a Onamae.com. The authoritative nameservers are ns1.verification-hold.suspended-domain.com and ns2.verification-hold.suspended-domain.com, both of which suggest a temporary verification hold status. DNS resolution points to IP address 104.21.21.57, which is associated with Cloudflare, Inc. (AS13335) and geolocated in the United States. No SSL/TLS certificate was presented, meaning connections to the host would be unencrypted. The site’s page title, as captured in the intelligence feed, reads “$BOUNTY | Highest USDT Rewards,” a phrase commonly used to lure cryptocurrency users.
The domain is explicitly listed as impersonating the Metamask brand, and the scam type is identified as Wallet/Seed Phishing employing a Wallet Connect abuse kit. Google Safe Browsing classifies the domain under social engineering, and one security blocklist has already flagged it. VirusTotal reports that 12 of 93 scanned security vendors flagged the domain, indicating moderate detection across the scanning community. PhishDestroy has also added the domain to its blocklist.
The current operational status is offline, which may reflect takedown efforts or a transient hosting change, but the infrastructure artifacts remain observable. Uncertainty remains regarding the exact content served before the takedown, as no live HTTP response or screenshot is available. Defenders should continue to block the domain at network perimeter and DNS layers, monitor for any re‑registration or similar naming patterns, and advise users of Metamask to disregard any unsolicited requests that reference “$BOUNTY” or promise USDT rewards. Ongoing threat‑intel feeds should be consulted for any resurgence of the wallet‑connect kit or related phishing infrastructure.
Cobertura dos dados12 recorded checks
Inteligência de segurança de rede
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Nextron YARA rules | 2ly2ut.com/main.bbc2594c9c69111e.js |
malware | Unique code from Jetriz, Swid & Jeniva of the Tetris framework |
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Captura armazenada
Inteligência de Domínios
Detalhes técnicosDNS, SANs do SSL, carimbos de data e hora
ICANN OVERSIGHT
Credenciamento e contexto RAA
Credenciamento e contexto RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Análise do VirusTotal
Evidências e relatórios externosIndependent lookups and source reports
PD-20260124-8BC9CD Recipient: abuse@internet.gmo Victim safety and official reportingImmediate actions and verified reporting channels
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.