amazon-coin[.]com
“Claim Your Share of the Arbitrum Ecosystem | Up to $25,000 for Active Wallets”
Resumo das evidências
On July 24, 2026 the domain amazon-coin.com was observed hosting a fake airdrop campaign that promised up to $25,000 for active wallets in the Arbitrum ecosystem. The site is currently offline, but historical records show that the domain resolved to the IP address 45.9.148.51, which is assigned to Nice IT Services Group Inc. in the Netherlands (AS49447). The domain was created on 21 February 2026 and was registered via Unstoppable Domains Inc., a registrar commonly used for cryptocurrency‑related domains. The TLS certificate presented on the site was identified as an R11‑grade certificate, indicating a low level of validation.
Reputation services rated the domain poorly: Gridinsoft gave it a score of 0/100, Scamadviser assigned 6/100, and the domain appears on a single security blocklist. VirusTotal analysis recorded detections from 2 of 93 antivirus engines, confirming malicious content despite the low detection count. The page title captured during the crawl—“Claim Your Share of the Arbitrum Ecosystem | Up to $25,000 for Active Wallets”—matches the typical language used in fraudulent airdrop schemes that lure cryptocurrency users with promises of large payouts. The campaign was flagged and taken down by the PhishDestroy blocklist, which now lists the domain as offline.
Evidence does not clarify the exact phishing kit or the full set of URLs that were served, and no screenshots or content snapshots are available. However, the combination of a freshly registered cryptocurrency‑related domain, a low‑trust SSL certificate, poor reputation scores, and the presence of a fake‑airdrop claim strongly suggests a financially motivated fraud operation targeting users of the Arbitrum network. Defenders should add 45.9.148.51 to network‑level deny lists, monitor for any resurrection of the domain or similar “amazon‑coin” patterns, and ensure that endpoint protection solutions are updated with the two VirusTotal detections.
Data Coverage
Pipeline de resposta a ameaças
Cobertura de listas de bloqueio
10 fontes externas monitoradas · instantâneo de 11/08/2026
10 fontes externas monitoradas Sem correspondência
Denúncias da comunidade
Denunciado por 1 membro da comunidade; visto pela primeira vez em 17/08/2025
- Denúncias armazenadas
- 1
- URLs únicas denunciadas
- 1
Captura armazenada
Inteligência de Domínios
Detalhes técnicosDNS, nomes TLS e datas
ICANN OVERSIGHT
Credenciamento e contexto RAA
Credenciamento e contexto RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Inteligência forense
Análise do VirusTotal
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo