gasfree[.]site
“GasFree — Send USDT on TRON Without TRX | Pay Fees in USDT”
gasfree.site — Conteúdo indisponível. Representação da marca: Across; Tipo de golpe: Credential Phishing. Resumo das evidências: VirusTotal 4/91 (alphaMountain.ai, CRDF, Gridinsoft, SOCRadar); 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 80/100. Registrador: Spaceship.
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
Analysis of the domain gasfree.site indicates that it was registered on July 10 2026 through the registrar Spaceship, Inc. The authoritative nameservers are launch1.spaceship.net and launch2.spaceship.net, which are typical of the registrar’s default configuration. DNS resolution points to the IPv4 address 186.2.175.35, confirming that the domain is currently reachable on the public Internet. The domain has been observed by the PhishDestroy mitigation service and is listed on a single external blocklist, suggesting that at least one security feed has flagged it as malicious. VirusTotal records show that the domain was submitted to 91 scanning engines; none of the engines returned a positive detection at the time of the scan.
While the lack of detections does not confirm benign behavior, it indicates that the payload or hosting infrastructure has not yet been catalogued by the majority of public scanners. The available intelligence classifies the activity as a generic credential harvesting campaign, but no page title, SSL certificate details, HTTP response codes, or content analysis have been disclosed, leaving the exact lure and victim profile undefined. Consequently, defenders cannot rely on content‑based signatures and must focus on network‑level indicators such as the IP address 186.2.175.35, the registrar footprint, and the observed nameserver pattern.
Recommended mitigation steps include adding the IP and domain to blocklists, configuring web‑proxy filters to deny outbound connections to the host, and monitoring DNS queries for the associated nameservers. Continuous re‑scanning with multi‑vendor services is advised to detect any future detection changes. The domain remains active as of the report date, and its short lifespan suggests a rapid‑deployment model typical of opportunistic phishing operations.
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Captura armazenada
Inteligência de Domínios
Detalhes técnicosDNS, SANs do SSL, carimbos de data e hora
ICANN OVERSIGHT
Credenciamento e contexto RAA
Credenciamento e contexto RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Cruzamento de inteligência de ameaças · source references
Tecnologias · 2 identified
Modernizr is a JavaScript library that detects the features available in a user's browser.
modernizr.com 100% de confiançaDDoS-Guard is a Russian Internet infrastructure company which provides DDoS protection, content delivery network services, and web hosting services.
ddos-guard.net 100% de confiançaAnálise do VirusTotal
Evidências arquivadas
Evidências e relatórios externos
PD-20260729-F04358 Recipient: abuse@spaceship.com Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo