app-backpack[.]co
Resumo das evidências
PhishDestroy has identified app-backpack.co as a malicious domain actively hosting a counterfeit login interface designed to harvest user credentials. This page mimics a legitimate authentication portal, likely impersonating a well-known cryptocurrency wallet or exchange platform, to trick visitors into entering their login details. Once captured, the stolen credentials are almost certainly used to drain digital assets or gain unauthorized access to financial accounts. Users who encounter this domain should not interact with it and should assume any entered credentials have been compromised.
This domain was flagged on March 29, 2026, and is registered through PDR Ltd. d/b/a PublicDomainRegistry.com. VirusTotal currently shows 4 out of 95 threat detection engines flagging the domain, indicating low AV coverage at this time. The domain resolves to IP address 172.67.208.46 and is secured with a Let's Encrypt SSL certificate, a common tactic used by phishing operators to appear legitimate. Despite the absence of AV detections, PhishDestroy’s behavioral analysis confirms malicious intent based on the page content and hosting infrastructure.
If you have visited app-backpack.co and entered any login details, immediately change your password on the legitimate platform and enable multi-factor authentication if available. Revoke any active sessions or API keys associated with the compromised account. Scan your device for malware using reputable security software and consider using a dedicated password manager that can warn about known phishing domains. Report this domain to PhishDestroy for analysis and community protection. Stay vigilant and always verify URLs before entering sensitive information.
Instantâneo das evidências enviadas
- Enviado
- Registros do livro-razão
- 1
- ID do caso
PD-20260526-FCE71C- Título da página capturada
- Just a moment...
- Artefato PDF
- Evidência em PDF
Base jurídica
Texto completo da evidência
Acceptable Use Policy (AUP): The domain app-backpack.co is engaged in phishing activities, which constitute a clear violation of your AUP prohibiting illegal activities and fraud.
Terms of Service (TOS): The continued operation of this domain violates your TOS, which reserves the right to suspend or terminate services for any fraudulent or deceptive practices.
Applicable Laws (Unknown):
Computer Fraud and Abuse Act (CFAA): This U.S. law prohibits unauthorized access to computers and networks, which is relevant if the phishing activities target users in the U.S.
Wire Fraud Statute (18 U.S.C. § 1343): This law addresses schemes to defraud individuals or entities using electronic communications, applicable to the fraudulent activities associated with this domain.
CAN-SPAM Act: This legislation regulates commercial email and prohibits misleading header information, which is often a component of phishing schemes.
Regulatory Note: Failure to act on this report may expose your organization to liability under applicable laws and regulations, as well as potential penalties for non-compliance with your own policies. Immediate action is recommended to mitigate risk.
Data Coverage
Inteligência de segurança de rede
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Hagezi Threat Feed | app-backpack.co |
malicious | Sinkholed |
| DNS4EU | app-backpack.co |
malicious | Sinkholed |
| Quad9 DNS | app-backpack.co |
malicious | Sinkholed |
Pipeline de resposta a ameaças
Cobertura de listas de bloqueio
10 fontes externas monitoradas · instantâneo de 11/08/2026
Denúncias da comunidade
Denunciado por 1 membro da comunidade; visto pela primeira vez em 30/03/2026
- Denúncias armazenadas
- 1
- URLs únicas denunciadas
- 1
Análise do VirusTotal
Análise de desempenho do site
Google PageSpeed Insights — mobile performance audit of app-backpack.co · checked Mar 30, 2026
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo