asterdex-update[.]xyz
“Aster - The next-gen perp DEX for all traders”
asterdex-update.xyz — Conteúdo indisponível. Representação da marca: Genericcrypto; Tipo de golpe: Credential Phishing. Resumo das evidências: VirusTotal 9/94 (alphaMountain.ai, CRDF, CyRadar, Emsisoft, Forcepoint ThreatSeeker); URLQuery 1 alert; URLScan malicious verdict; 3 external blocklist matches (MetaMask, ScamSniffer, SEAL); PhishDestroy score 81/100. Registrador: PDR.
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
PhishDestroy identifies asterdex-update.xyz as a live credential phishing domain designed to steal login credentials under the guise of a software update for Asterdex users. The site mimics legitimate update prompts to trick victims into entering their usernames and passwords, which are then harvested by attackers for account takeovers or sold on dark web markets. This domain resolves to IP 188.114.97.3 and was registered through PDR Ltd. d/b/a PublicDomainRegistry.com on March 27, 2026. Although Let's Encrypt issued an SSL certificate to boost credibility, VirusTotal currently reports 0 detections across 95 security engines, indicating it has evaded immediate detection by antivirus solutions.
This domain represents a targeted threat masquerading as a routine software update portal. Registrant anonymity and the use of a free Let's Encrypt certificate are common tactics to appear legitimate while hosting phishing payloads. The short domain age—created just days ago—and low detection rate suggest it is a newly launched campaign with potential to expand rapidly. Users who interact with this site risk exposing sensitive credentials to threat actors who may reuse them across multiple platforms.
If you visited or entered any information on asterdex-update.xyz, immediately change passwords for the affected account(s) and enable multi-factor authentication on all related services. Scan your device using updated antivirus software to detect any installed malware. Report the domain to your IT administrator or security team and avoid clicking any links or downloading files from this site. Monitor financial and email accounts for signs of unauthorized access. Consider using a password manager with built-in phishing detection to block similar future attempts.
Inteligência de segurança de rede
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DNS4EU | asterdex-update.xyz |
malicious | Sinkholed |
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Captura armazenada
Inteligência de Domínios
Detalhes técnicosDNS, SANs do SSL, carimbos de data e hora
ICANN OVERSIGHT
Credenciamento e contexto RAA
Credenciamento e contexto RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Inteligência forense
Tecnologias · 3 identified
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
Web infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
Análise do VirusTotal
Análise de desempenho do site
Google PageSpeed Insights — mobile performance audit of asterdex-update.xyz · checked Mar 28, 2026
Evidências e relatórios externos
PD-20260327-CC38A1 Recipient: abuse@publicdomainregistry.com Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo