Pesquise domínios monitorados e analise as evidências armazenadas, as detecções e a disponibilidade mais recente observada.
219,779
Total rastreado
213,476
VT detectado
91,884
Visto pela última vez: Ativo
127,895
Indisponível na última verificação
541
VT Pendente
How This Attack Works
Fake Token Presale scams trick victims into believing they are investing in legitimate cryptocurrency projects. Here's how the scam typically unfolds:
STEP 1
Create Fake Websites
Scammers set up realistic-looking websites mimicking legitimate token presale portals.
STEP 2
Promote Presale on Social Media
Using social media and fake endorsements, scammers attract potential investors.
STEP 3
Collect Cryptocurrency
Victims are prompted to send cryptocurrency to a specified address under the guise of buying tokens.
STEP 4
Disappear with Funds
Once funds are collected, scammers shut down the site and disappear, leaving victims without recourse.
Technical Analysis
Fake Token Presale scams often leverage phishing tactics combined with cryptocurrency-specific techniques. Attackers use homograph attacks to create URLs that closely resemble legitimate sites, often registered through top registrars like NICENIC INTERNATIONAL GROUP CO., LIMITED and PDR Ltd. d/b/a PublicDomainRegistry.com. They exploit the decentralized nature of blockchain networks, utilizing smart contracts that mimic legitimate presale contracts but are programmed to divert funds to the attacker’s wallet. The infrastructure often involves cloud-based hosting services to quickly deploy and dismantle sites, minimizing the chance of detection. HTML and JavaScript are commonly used to create dynamic, convincing interfaces that reassure potential victims of the site’s legitimacy. Additionally, attackers might deploy SEO techniques to improve the visibility of their fraudulent sites in search engine results, further increasing their reach.
Real Cases
CryptoX Presale Scam (2024)
$2 million stolen
A fake presale for a non-existent token, CryptoX, duped investors into contributing significant sums.
TokenLaunch Fraud (2023)
$1.5 million stolen
Victims were lured into a fake token launch with promises of high returns, only for the site to vanish post-collection.
QuickCoin Deception (2024)
$3 million stolen
Scammers created a sophisticated site mimicking a known exchange, leading to substantial financial losses.
How to Detect
Verificar for slight misspellings in domain names.
Look for inconsistent branding or layout compared to legitimate sites.
Be wary of unsolicited investment opportunities via social media.
Verify presale details on official project channels.
Beware of high-pressure tactics urging immediate investment.
How to Protect Yourself
1
Always verify URLs before entering personal information.
2
Use browser extensions to detect phishing attempts.
3
Consult official project websites or channels for presale information.
4
Enable two-factor authentication on cryptocurrency exchanges.
5
Relatório suspicious sites to authorities and platforms like PhishDestroy.
Frequently Asked Questions
Data sourced from PhishDestroy threat intelligence database — 689 domains tracked for this threat type
Fake Token Presale 689 domains

binance-dep30h.com

bitcoinhyper.connect-portal.live

dreamsmart.pl

liquidchains.info

xdnaprotocol.com

claims-bitcoinhyper.com

coiniist-rainbow.xyz

llittlepepe.com

pepeheimer.io

spcx-network.com

test-023492023.com

agaricproku.com

blockchainfx.world

blockdag-network-miners.pages.dev

claim-basedawgz.pages.dev

claims-snortertoken.com

deepsnitchs-ai.claims

grok18k.info

grok33k.info

grokvarum.com

grokvitrium.com

hotoj.guru

lunexnetwork.com

moonbagorg.pages.dev

murad-presale.com

presales-monprotocolapp.pages.dev

prizelink.net

spx88k.com

xa60zlaunch.com

xa909k.com

basedawgz.pages.dev

blazpay.org

claimmoonbag.pages.dev

coinlist-rainbow.xyz

cryptoallstars-claimslive.pages.dev

dep29k-binance.com

evidizayn.com

grok44k.digital

littlepepesite.pro

monoprotocol.info

presale-99bitcoins.pages.dev

presale-sat0.com

retik-finance-io.pages.dev

snorterbotclaim.pages.dev

sonami-so.info

spx66x.com

spx88k-centurylink.com

spx88k-fxempire.com

spx98k.com

thecrito.guru

timwarrencoin.io

xa20r.com

xa40p.net

xa500k.com

xa60r.com

xa90p.org

zama.sale

003-bca.net

appie.shop

basedawgz-ae.pages.dev

basedawgz-app.pages.dev

bestwalletnow.com

btchyperapp.pages.dev

claim-cryptoallstars-cco.pages.dev

claim-jindocoin.pages.dev

cradwin.com

dashboard-bestwallet.firebaseapp.com

dep26k-binance.com

getretiksale.pages.dev

gro82x.org

grok82c-cointelegraph.com

grok87k-cointelegraph.com

grok87k.com

invest-xai.com

moonbull.io

mpeppe-live.pages.dev

myxaicoin.pages.dev

pepeheimer-claim.com

pepeheimer-claimlives.pages.dev

purchase2-blockdags-networks.pages.dev

ripplecareer.com

spx40k.net

spx80k.com

wallstreetpepe-online-d3n.pages.dev

xa98b.net

best-wallettoken.com

blockdag-server.web.app

btcbullsapp.pages.dev

claim-pepenode.io

colnilst.co

cryptoallstarsio-sale.pages.dev

debraleslie.com

gro34d-cointelegraph.com

grokai-network.net
Pipeline de resposta a ameaças
Como cada domínio neste hub é verificado e como as ameaças confirmadas são neutralizadas. Visualização completa do pipeline →
Verificações de inteligência contra ameaças— cada domínio é verificado e comparado com:
urlscan.ioCaptura de tela · DOM · HTTPVirusTotal90+ AV enginesGoogle Safe BrowsingTransparency RelatórioCloudflare RadarDNS · certs · categoriesAlienVault OTXThreat-intel pulsesWayback MachineHistorical evidenceabuse.ch ThreatFoxIOC correlationcrt.shCertificate TransparencyDNS Segurança FiltersQuad9 · AdGuard · CleanBrowsingWeb-VerificarFull surface scan
Sincronização Global de Fornecedores— as detecções confirmadas são enviadas a 29 parceiros:
GoogleSafe BrowsingGoogleWeb Risk APIMicrosoftSmartScreenVirusTotalDetection feedCloudflareRadar / 1.1.1.1YandexSafe BrowsingURLScan.ioPublic scanESETWebGuardBitdefenderThreat exchangeNortonSafe WebSymantecAvaliação do siteAviraCloud detectionAvast / AVGWeb ShieldKasperskyOpenTIPDr.WebOnline scannerNetcraftRemoção APIPhishTankVerified voteAPWG eCXBulk feedPhishStatsOpen feedPhish.RelatórioHosting abuseSpamhausDBL feedPolySwarmMarketplaceCheckPhishBolster scanQutteraMalware scanURLquerySandboxCriminal IPAsset intelCRDFThreat CenterScamadviserTrust scoreMyWOTWeb of Trust