nodesx[.]cc
“NodeX”
Resumo das evidências
The domain nodesx.cc was observed as a brand‑impersonation site targeting Binance. Registration records show it was created on 27 August 2025 via Dominet (HK) Limited, and the domain is presently taken offline. No TLS certificate is presented, indicating HTTP‑only access at the time of capture. DNS resolution points to the address 172.67.134.48, which belongs to AS13335 Cloudflare, Inc. and is geolocated to the United States. The authoritative name servers listed include johnathan.ns.cloudflare.com, ns1.domainnamedns.com, ns2.domainnamedns.com, and olga.ns., reflecting a mixed use of Cloudflare‑managed and third‑party DNS services.
Analysis on VirusTotal reports that twelve of ninety‑five antivirus and URL‑filtering engines flagged the domain, providing independent corroboration of malicious intent. The site appears on two public security blocklists and is specifically listed by PhishDestroy and ScamSniffer, reinforcing its classification as a phishing‑related resource. Independent reputation scoring from Gridinsoft assigns a trust rating of zero out of one hundred, suggesting an extreme lack of legitimacy. The page title returned by the server is “NodeX”, which does not reference the targeted brand and offers no additional context about the content served. The only explicit brand association comes from the intelligence label “Impersonates: binance”, indicating that the infrastructure was likely used to lure Binance users.
No further details about the site’s HTML, form fields, or credential‑capture mechanisms are available, leaving the precise attack vector uncertain. Defenders should continue to block the domain and its underlying IP address at network perimeter devices, and add nodesx.cc to URL filtering and DNS sinkhole lists. Monitoring for future re‑activation of the same domain or for additional domains registered by Dominet (HK) Limited that resolve to the same Cloudflare edge nodes is advisable.
Data Coverage
Pipeline de resposta a ameaças
Cobertura de listas de bloqueio
10 fontes externas monitoradas · instantâneo de 11/08/2026
9 fontes externas monitoradas Sem correspondência
Linha do tempo de detecção
-
Cloudflare Radar
Varredura do Cloudflare Radar armazenada · Abrir varredura
Análise do VirusTotal
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo