jointflowx[.]com
“JointflowX”
Resumo das evidências
Analysis of the domain jointflowx.com indicates active brand impersonation targeting Ethereum, classified as a high-risk crypto scam. The domain was registered on November 4, 2025, through Dynadot LLC and currently resolves to the IP address 5.196.175.67, hosted on AS16276 (OVH SAS) in France. The domain returns an HTTP 200 status, signaling an operational web server, and is served over HTTPS with a Let's Encrypt SSL certificate (serial E7). Nameservers are configured as ns3.ddoscure.com and ns4.ddoscure.com, a pattern observed in other low-reputation domains.
Detection data from security vendors shows 13 of 95 engines on VirusTotal flagging the domain as malicious, while it appears on at least one security blocklist, specifically PhishDestroy. The page title 'JointflowX' and the scam classification as a crypto scam align with the stated brand target, Ethereum, though the exact content and mechanics of the scam remain unconfirmed due to limited public telemetry. Infrastructure analysis reveals the use of common frontend libraries and frameworks, including particles.js, UIKit, jQuery, and the Smartsupp chat widget, alongside Nginx as the web server. The Gridinsoft trust score of 0/100 further corroborates the domain's high-risk classification.
While the domain's creation date is recent relative to the report date of July 23, 2026, no anomalies in registration timing are evident. Defenders are advised to block the domain at the DNS or proxy level, monitor associated IP 5.196.175.67 for lateral movement, and review logs for connections to the nameservers ns3.ddoscure.com and ns4.ddoscure.com. Additional scrutiny of domains registered via Dynadot LLC with similar naming conventions or hosting patterns may uncover related threats. Given the domain's active status and detection by multiple security vendors, immediate containment measures are recommended for environments handling cryptocurrency or Ethereum-related transactions.
Data Coverage
Pipeline de resposta a ameaças
Cobertura de listas de bloqueio
10 fontes externas monitoradas · instantâneo de 10/08/2026
10 fontes externas monitoradas Sem correspondência
Captura armazenada
Inteligência de Domínios
Detalhes técnicosDNS, nomes TLS e datas
ICANN OVERSIGHT
Credenciamento e contexto RAA
Credenciamento e contexto RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Análise do VirusTotal
Análise de desempenho do site
Google PageSpeed Insights — mobile performance audit of jointflowx.com · checked Mar 2, 2026
Análise da configuração do site
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo