onocoy-token[.]gate-cryptolist[.]com
“CRYPTOLIST”
onocoy-token.gate-cryptolist.com — Conteúdo indisponível. Tipo de golpe: Credential Phishing. Resumo das evidências: VirusTotal 14/91 (ADMINUSLabs, BitDefender, Chong Lua Dao, CRDF, CyRadar); PhishDestroy score 92/100.
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
On July 29 2026 the domain onocoy-token.gate-cryptolist.com was identified as an active credential‑harvesting site. Infrastructure analysis shows the domain resolves to the IPv4 address 188.114.96.3. The hosting IP is owned by a provider that is frequently observed in malicious campaigns, increasing the likelihood that the server is being used to host phishing content. DNS queries return no nameserver records, indicating either deliberate concealment or a misconfigured authoritative zone. The domain appears on a single security blocklist and is explicitly blocked by the PhishDestroy feed, confirming that at least one reputable anti‑phishing service has taken mitigation action.
VirusTotal reports that 14 out of 91 antivirus and URL scanning engines flag the domain as malicious, providing independent corroboration of its threat status. Publicly available intelligence does not include a page title, SSL certificate details, HTTP response codes, or any observed brand targeting, so the precise content served by the site remains unknown. Likewise, no information on the registrar, ASN, or geographic location is disclosed in the current dataset. The absence of these data points limits the ability to attribute the infrastructure to a specific threat actor, but the combination of a known malicious hosting IP, blocklist presence, and multi‑vendor detections is sufficient to classify the domain as high‑risk.
Defenders should add onocoy-token.gate-cryptolist.com to DNS‑based deny lists and block outbound connections to 188.114.96.3 at the network perimeter. Continuous monitoring of DNS query logs for the domain or its IP can reveal compromised internal hosts. Integrating the domain into existing security information and event management (SIEM) correlation rules will enable early detection of credential‑theft attempts.
Inteligência de segurança de rede
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Captura armazenada
Inteligência de Domínios
Detalhes técnicosDNS, SANs do SSL, carimbos de data e hora
Análise do VirusTotal
Evidências e relatórios externos
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo