railgun-privacy[.]gitbook[.]io
“Overview | Wiki”
railgun-privacy.gitbook.io — Não verificado. Representação da marca: Arbitrum; Tipo de golpe: Crypto Scam. Resumo das evidências: VirusTotal 2/91 (ChainPatrol, alphaMountain.ai); PhishDestroy score 76/100. Registrador: Cloudflare.
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
This domain, railgun-privacy.gitbook.io, is currently flagged as a high‑risk brand‑impersonation site targeting Arbitrum. Infrastructure analysis shows the hostname resolves to 172.64.147.209, an address owned by Cloudflare, Inc. (AS13335) located in the United States. The domain uses Cloudflare‑provided nameservers dahlia.ns.cloudflare.com and hugh.ns.cloudflare.com, and the TLS certificate is issued by Google Trust Services under the WE1 root, confirming a valid HTTPS handshake. HTTP requests receive a 307 temporary redirect response, and the page title reported by passive scanners is “Overview | Wiki”, which does not disclose any Arbitrum‑related content but suggests a generic documentation layout. The site is built on GitBook and also leverages Google Cloud, Vercel, HSTS, Google Cloud Trace and HTTP/3, indicating a modern stack that may be used to host malicious content while appearing legitimate.
The brand indicator list identifies the domain as impersonating Arbitrum, and the scam classification is recorded as a crypto‑scam. The domain was created on 30 March 2014 and is registered through Cloudflare, Inc. The Gridinsoft trust score of 0 / 100 reflects a lack of confidence in the host’s reputation. Detection telemetry shows the domain appears on a single security blocklist and is actively blocked by PhishDestroy. VirusTotal scans have returned detections from two of ninety‑five vendors, reinforcing the malicious assessment. Defenders should treat any traffic to railgun-privacy.gitbook.io as hostile.
Blocking at the DNS or proxy layer is advised, and existing security controls that reference the listed blocklist should be updated to include the domain. Continuous monitoring of the IP address 172.64.147.209 for any new payloads or command‑and‑control activity is recommended, as the underlying Cloudflare infrastructure can be reused for other campaigns.
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Tecnologias · 7 identified
Suite of cloud computing services running on Google infrastructure.
Cloud platform for frontend deployment, optimized for Next.js.
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
Web infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
Análise do VirusTotal
Evidências arquivadas
Análise de desempenho do site
Google PageSpeed Insights — mobile performance audit of railgun-privacy.gitbook.io · checked Mar 7, 2026
Evidências e relatórios externos
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo