Notification and current-status evidence
The sent-report ledger records the first outgoing report at .
The recorded recipient is whoisrequest@markmonitor.com.
The latest stored availability evidence still shows the domain reachable; 4 months has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
cdn2[.]028426[.]com
“404 - Quick Tip | Cofense”
cdn2.028426.com — Encoberto · alcançável. Tipo de golpe: Generic Phishing. Resumo das evidências: VirusTotal 11/91 (ADMINUSLabs, BitDefender, ESET, Emsisoft, G-Data); URLQuery 2 alerts; cloaking observed; PhishDestroy score 89/100. Registrador: MarkMonitor.
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
PhishDestroy identifies cdn2.028426.com as an elevated risk domain engaged in a crypto drainer scam. This specific threat aims to trick users into revealing cryptocurrency wallet credentials or private keys, potentially resulting in irreversible financial losses.
This domain was first registered on January 12, 2017, and is registered through MarkMonitor, Inc., a well-known domain registrar. It resolves to the IP address 34.194.247.17 and uses an SSL certificate issued by Let's Encrypt. VirusTotal analysis flags it with 15 out of 95 security vendors categorizing it as malicious. Additionally, cdn2.028426.com appears on two security blocklists and is actively blocked by both OpenPhish and PhishingArmy, indicating strong consensus about its malicious intent.
To mitigate risks associated with this crypto drainer scam, users should never enter wallet credentials or private keys on this domain or any untrusted sites. Employing hardware wallets or multi-factor authentication for cryptocurrency accounts can provide additional security. Users are advised to verify suspicious domains on trusted platforms like PhishDestroy before interacting with them and to keep security software up to date. Avoid clicking on unsolicited links claiming to be related to cryptocurrency transactions or wallets that lead to cdn2.028426.com or similar flagged domains.
Inteligência de segurança de rede
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Hagezi Threat Feed | cdn2.028426.com |
malicious | Sinkholed |
| DNS4EU | cdn2.028426.com |
malicious | Sinkholed |
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Captura armazenada
Inteligência de Domínios
Detalhes técnicosDNS, SANs do SSL, carimbos de data e hora
ICANN OVERSIGHT
Registration: 028426.com
Credenciamento e contexto RAA
Credenciamento e contexto RAA
Registrar accreditation and DNS abuse obligations
For the registrable domain 028426.com behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Tecnologias · 1 identified
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
Análise do VirusTotal
Análise de desempenho do site
Google PageSpeed Insights — mobile performance audit of cdn2.028426.com · checked Mar 29, 2026
Análise da configuração do site
Evidências e relatórios externos
PD-20260329-57D5C6 Recipient: whoisrequest@markmonitor.com Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo