paradex[.]biz
“Paradex”
paradex.biz — Não verificado. Representação da marca: WalletConnect; Tipo de golpe: Brand Impersonation. Resumo das evidências: VirusTotal 3/91 (CRDF, Gridinsoft, SOCRadar); PhishDestroy score 71/100. Registrador: Dynadot.
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
PhishDestroy identifies paradex.biz as an active crypto-drainer domain impersonating the Paradex exchange. The site is configured to intercept wallet connections and siphon assets under the guise of a legitimate trading interface. Security telemetry shows a drainer kit embedded in the page load, automating token approvals and transfer calls once a victim connects a wallet. The domain leverages visual cues such as logo, color scheme, and page layout to mirror the official Paradex site (paradex.io), increasing the likelihood of credential theft and fund misappropriation among traders familiar with the brand.
Technical indicators confirm the hostile nature of paradex.biz. VirusTotal currently scores the domain 1/95 detections (no AV signatures), suggesting it is newly weaponized and undetected by most engines. The domain resolves to IP 54.215.31.113 and is registered through Dynadot Inc on October 27, 2025, indicating very recent acquisition. A Let’s Encrypt SSL certificate lends superficial legitimacy, while Google Safe Browsing has not yet flagged the host. Current blocklist coverage is minimal, leaving most users exposed.
The domain remains active and under investigation with medium confidence in the threat classification. PhishDestroy recommends immediate network-level blocking of 54.215.31.113 and DNS sinkholing of paradex.biz. Users should verify exchange domains via official channels and avoid clicking links from unsolicited messages. Remaining risk is elevated due to undetected status and high mimicry fidelity; proactive takedowns and AV signature updates are the fastest mitigation paths.
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Captura armazenada
Inteligência de Domínios
Detalhes técnicosDNS, SANs do SSL, carimbos de data e hora
ICANN OVERSIGHT
Credenciamento e contexto RAA
Credenciamento e contexto RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Tecnologias · 5 identified
Cloud computing platform offering compute, storage, and networking services.
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
Amazon Web Services CDN for low-latency content delivery.
Third major version of HTTP protocol, built on QUIC for faster, more reliable connections.
Análise do VirusTotal
Evidências e relatórios externos
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo