rucds[.]com
Verificação de phishing e segurança de rucds.com
“MicroBull”
rucds.com — Conteúdo indisponível (HTTP 502). Tipo de golpe: Credential Phishing. Resumo das evidências: VirusTotal 2/94 (G-Data, URLQuery); URLQuery 2 det.; PhishDestroy score 60/100. Registrador: Porkbun.
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
PhishDestroy identifies rucds.com as a live generic phishing domain engineered for credential theft, not just generic phishing. The domain does not match any single brand impersonation or deploy a known crypto drainer kit at this time; instead it harvests user credentials through a spoofed login portal. Registrant behavior and page content suggest opportunistic harvesting intended for wallet exfiltration or exchange account takeover. Further analysis of the landing page confirms a credential capture form mimicking a prominent crypto service login without direct ties to a specific drainer service pack. The threat remains under investigation for expansion into drainer toolkits or targeted brand impersonation. rucds.com resolves to IP 188.114.97.3 and was registered on December 18, 2025 through Porkbun LLC. The domain holds a Google Trust Services SSL certificate and currently shows 0 detections on VirusTotal out of 95 engines. As of the last scan, this domain has not been listed on any public blocklists maintained by Google Safe Browsing or commercial threat feeds. The combination of a fresh domain, zero detections, and use of a branded SSL certificate suggests a recently activated attack chain. Current indicators point to low prior reputation across defenses, increasing the risk of successful user compromise. The campaign is actively live and has not been sinkholed or blocked by major browsers or security platforms. At present, the risk level is classified as under investigation due to limited telemetry and no confirmed drainer payload delivery. Immediate user guidance includes avoiding any login attempts on rucds.com, verifying wallet access only through official URLs, enabling 2FA, and reporting the domain to security teams or browsers via Google Safe Browsing submission. Monitoring for expansion into drainer deployment or targeting of specific exchanges is recommended. Remaining risk remains moderate due to fresh infrastructure and low detection coverage, warranting continued scrutiny and proactive blocking where feasible.
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Captura armazenada
Inteligência de Domínios
Detalhes técnicosDNS, SANs do SSL, carimbos de data e hora
ICANN OVERSIGHT
Credenciamento e contexto RAA
Credenciamento e contexto RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Tecnologias · 4 identified
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
Performance monitoring tool that measures website speed from real users.
www.cloudflare.comWeb infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
Análise do VirusTotal
Análise de desempenho do site
Google PageSpeed Insights — mobile performance audit of rucds.com · checked Apr 18, 2026
Evidências e relatórios externos
PD-20260418-F56E96 Recipient: abuse@porkbun.com Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo