raydiumdex[.]org
“Swap Raydium | Solana DEX”
Resumo das evidências
raydiumdex.org is currently offline according to the latest scan on July 24, 2026. The domain was registered on October 30, 2025 through CSL Computer Service Langenbach GmbH d/b/a joker.com and is served by the Cloudflare nameservers dara.ns.cloudflare.com and jeremy.ns.cloudflare.com. DNS resolution points to the IP address 188.114.96.3, which belongs to AS13335 Cloudflare, Inc., and is geolocated in the United States. No TLS certificate is presented for the host, indicating that HTTPS is not configured. The site title observed in earlier captures reads "Swap Raydium | Solana DEX", and the domain is explicitly listed as impersonating the Raydium brand, targeting users of the Solana decentralized exchange.
The malicious activity is classified as wallet/seed phishing, aiming to harvest private keys or recovery phrases. Threat intelligence shows that the domain is listed on one public security blocklist and has been blocked by the PhishDestroy service. VirusTotal analysis reports that 2 of 95 scanning engines flagged the domain as malicious, reinforcing the phishing classification. No additional evidence from Safe Browsing, Open Threat Exchange, or other reputation services is available in the current dataset. Uncertainty remains regarding the exact payload delivered to victims, as the page content has not been captured in this assessment.
Defenders should therefore treat the domain as high-risk. Recommended mitigation steps include adding 188.114.96.3 to network deny lists, blocking raydiumdex.org at DNS and proxy layers, and updating endpoint protection rules to flag any attempts to contact the domain. Users of Raydium and Solana DEX services should be warned not to enter wallet seeds or private keys on any site bearing the raydiumdex.org address. Continuous monitoring of the IP and associated Cloudflare identifiers is advised in case the infrastructure is repurposed for further phishing campaigns.
Data Coverage
Pipeline de resposta a ameaças
Cobertura de listas de bloqueio
10 fontes externas monitoradas · instantâneo de 12/08/2026
10 fontes externas monitoradas Sem correspondência
Linha do tempo de detecção
-
Cloudflare Radar
Varredura do Cloudflare Radar armazenada · Abrir varredura
Captura armazenada
Inteligência de Domínios
Detalhes técnicosDNS, nomes TLS e datas
ICANN OVERSIGHT
Credenciamento e contexto RAA
Credenciamento e contexto RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Análise do VirusTotal
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo