ctrldesktop[.]xyz
“Ctrl Wallet”
Resumo das evidências
The domain ctrldesktop.xyz was registered on February 21, 2026 through Tucows Domains Inc. and is currently listed as offline. The site presents the page title “Ctrl Wallet”, indicating a cryptocurrency‑wallet impersonation consistent with the observed “Crypto Scam” classification. No TLS certificate is associated with the host, confirming that the service was delivered over plain HTTP when it was reachable. DNS resolution points to the Cloudflare edge address 188.114.96.3, an IP owned by AS13335 Cloudflare, Inc. in the United States. The domain is served by the Cloudflare authoritative name servers melinda.ns.cloudflare.com and uriah.ns.cloudflare.com, a configuration commonly shared among many unrelated legitimate sites, which reduces the discriminative value of the hosting alone.
Threat intelligence sources flag the domain on a single external blocklist and it is explicitly blocked by the PhishDestroy service. The Open Threat Exchange records a single pulse referencing the domain, reinforcing its association with malicious activity. VirusTotal scans returned detections from 12 of 93 security vendors, providing independent confirmation of its malicious nature. No additional evidence such as Safe Browsing status or further community reports is available.
Uncertainty remains regarding the exact payload or credential‑harvesting mechanisms that may have been hosted at the URL, as the site is no longer reachable for direct analysis. Consequently, defenders should treat the domain as a confirmed malicious indicator. Recommended actions include adding ctrldesktop.xyz to DNS and proxy deny lists, enforcing block policies on the associated IP 188.114.96.3, and monitoring for newly registered domains that resolve to the same Cloudflare edge nodes or reuse the same registrar. Continuous ingestion of updated threat feeds will help capture any resurgence of the campaign or related infrastructure.
Instantâneo das evidências enviadas
- Enviado
- Registros do livro-razão
- 1
- ID do caso
PD-20260215-43F986- Título da página capturada
- Ctrl Wallet
- Artefato PDF
- Evidência em PDF
Texto completo da evidência
Acceptable Use Policy (AUP): The domain ctrldesktop.xyz is engaged in phishing activities, which is a direct violation of your AUP prohibiting illegal activities and fraud.
Terms of Service (TOS): The continued operation of this domain constitutes a breach of your TOS, which reserves the right to suspend or terminate services for any activities that involve deception or fraud.
Applicable Laws (KN):
Computer Misuse Act, 2003: This law criminalizes unauthorized access and use of computer systems, which includes phishing schemes.
Electronic Transactions Act, 2014: This legislation addresses fraudulent electronic communications, including phishing, and imposes penalties for such activities.
Regulatory Note: Failure to take immediate action against this domain may expose your organization to legal liability and regulatory scrutiny under applicable laws. It is imperative to act swiftly to mitigate potential risks associated with non-compliance.
Data Coverage
Pipeline de resposta a ameaças
Cobertura de listas de bloqueio
10 fontes externas monitoradas · instantâneo de 11/08/2026
10 fontes externas monitoradas Sem correspondência
Linha do tempo de detecção
-
Cloudflare Radar
Varredura do Cloudflare Radar armazenada · Abrir varredura
Captura armazenada
Inteligência de Domínios
Detalhes técnicosDNS, nomes TLS e datas
ICANN OVERSIGHT
Credenciamento e contexto RAA
Credenciamento e contexto RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Análise do VirusTotal
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo