superjoinamply[.]com
Verificação de phishing e segurança de superjoinamply.com
“Website Design and Development for High-Growth B2B | Amply”
superjoinamply.com — Conteúdo indisponível (HTTP 502). Tipo de golpe: Generic Phishing. Resumo das evidências: VirusTotal 3/91 (CRDF, Gridinsoft, SOCRadar); PhishDestroy score 65/100. Registrador: Porkbun.
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
PhishDestroy identifies superjoinamply.com as an active crypto drainer domain designed to siphon cryptocurrency assets from unwitting users. The page impersonates legitimate crypto-related services to trick victims into connecting wallets or signing malicious transactions. No specific drainer kit signature was observable in public scans, but behavior aligns with generic drainer scripts embedded through obfuscated JavaScript payloads served via the compromised or attacker-controlled page. The domain abuses trust in recognizable branding (mimicking “Join” and “Ampl” in naming) to appear credible at a glance, leveraging urgency and technical jargon to prompt hasty wallet connections. Despite its infancy, the infrastructure is already weaponized and should be treated as a live threat vector to crypto users.
Technical indicators confirm the domain is hostile: VirusTotal currently shows 0/95 security engines flagging the URL as malicious, a common early-stage evasion window for novel campaigns. The domain resolves to IP 188.114.96.3, hosted on Cloudflare infrastructure that masks origin IPs and complicates takedowns. Registered anonymously through Porkbun LLC on June 17, 2024, the domain obtained an SSL certificate from Google Trust Services, adding a veneer of legitimacy. Google Safe Browsing (GSB) has not yet blacklisted this domain, and public blocklists show zero listings—indicating a fresh, low-reputation entry in the drainer ecosystem. These factors combine to create a high-impact, low-detection threat ideal for harvesting private keys or draining wallets within minutes of user interaction.
Status remains active with no takedown or mitigation visible. Immediate actions include blocking 188.114.96.3 at firewall and DNS levels, flagging the domain in enterprise and endpoint controls, and updating browser policies to intercept requests to superjoinamply.com. Users should avoid visiting the domain entirely; crypto users should verify all transaction prompts using hardware wallets or reputable dApps. Remaining risk is classified as HIGH due to zero detections and active deployment lifecycle. Continuous monitoring and rapid block propagation are required to prevent further exploitation while awaiting GSB and security vendor updates.
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Captura armazenada
Inteligência de Domínios
Detalhes técnicosDNS, SANs do SSL, carimbos de data e hora
ICANN OVERSIGHT
Credenciamento e contexto RAA
Credenciamento e contexto RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Tecnologias · 16 identified
Visual website builder with hosted publishing.
Conversion-tracking pixel by LinkedIn — B2B ad audience measurement.
Free public CDN for open-source projects, serving files from npm and GitHub.
Fast, small JavaScript library simplifying HTML manipulation, event handling, and Ajax.
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
Tag management system for deploying marketing and analytics tags.
tagmanager.google.comWeb analytics service tracking website traffic and user behavior.
marketingplatform.google.comConversion-tracking pixel by Meta — logs page views and custom events to Facebook/Instagram ad accounts.
www.facebook.comWeb infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
Análise do VirusTotal
Análise de desempenho do site
Google PageSpeed Insights — mobile performance audit of superjoinamply.com · checked Apr 7, 2026
Evidências e relatórios externos
PD-20260329-83741A Recipient: abuse@porkbun.com Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo