subcoin[.]click
“SubCoin”
Resumo das evidências
PhishDestroy identifies www.subcoin.click as an active fake wallet-drainer host designed to trick users into surrendering private crypto keys and drain assets directly from their wallets. The domain presents itself as a legitimate ‘SubCoin’ wallet service but is a turnkey phishing package preloaded with JavaScript that automatically signs and executes unauthorized transactions once victims connect a wallet and grant a malicious signature request. Seed b7300f confirms this campaign is currently in the wild and not a generic phishing page but a specialized drainer kit marketed to cyber-criminals on dark-web forums. No known brand is being abused at this time, and the kit itself is proprietary rather than a cloned interface of an existing service. This domain was flagged on August 28 2024 and resolves to IPv4 address 46.62.172.27. The domain was registered through Hostinger operations UAB less than 48 hours ago, giving it an extremely young age profile which increases the risk of fresh malicious content. A Let’s Encrypt SSL certificate is already provisioned, likely to evade browser warnings and lend false legitimacy to phishing pages served under https://subcoin.click. VirusTotal currently shows 0 detections out of 95 engines, indicating the payload has not yet been widely fingerprinted. Google Safe Browsing (GSB) has no record for this domain, and public blocklists such as PhishTank and OpenPhish currently list zero entries for www.subcoin.click, underscoring the novelty and swift deployment of the threat. The current operational status is labeled active, meaning the drainer kit is live and potentially being pushed via spam, social media, or malvertising. Immediate defensive actions include blocking the domain at DNS and firewall layers, disabling inbound TLS connections to 46.62.172.27, and flagging the SHA-256 hashes of any wallet-drainer assets distributed from this host for endpoint blocking. Despite the young age and zero VT detections, the combination of a turnkey wallet-drainer package, recent registration, and lack of blocklist coverage places the residual risk at HIGH until widespread detection signatures emerge. Users should avoid any links mentioning SubCoin or similar crypto wallet services and treat unsolicited wallet connection prompts as hostile regardless of the domain’s SSL status.
Data Coverage
Pipeline de resposta a ameaças
Cobertura de listas de bloqueio
10 fontes externas monitoradas · instantâneo de 13/08/2026
10 fontes externas monitoradas Sem correspondência
Captura armazenada
Inteligência de Domínios
Detalhes técnicosDNS, nomes TLS e datas
ICANN OVERSIGHT
Credenciamento e contexto RAA
Credenciamento e contexto RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Tecnologias
11 tecnologias identificadas com alta confiança
Análise do VirusTotal
Análise de desempenho do site
Google PageSpeed Insights — mobile performance audit of subcoin.click · checked Apr 25, 2026
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo