tcsdshop[.]com
“Drainer MetaMask • 400,00 $”
Resumo das evidências
Analysis as of July 22 2026 indicates that the domain tcsdshop.com was registered on February 21 2026 and currently resolves to the IP address 188.114.97.3, which is hosted by Cloudflare, Inc. (ASN 13335) and geolocated to the United States. The site presented the page title “Drainer MetaMask • 400,00 $”, suggesting a crypto‑draining operation targeting MetaMask users. The SSL certificate is identified as “WE1”, confirming that transport‑layer encryption was in place at the time of observation. The domain has been flagged by the PhishDestroy blocklist and appears on one additional security blocklist, reinforcing its classification as a crypto‑related scam.
VirusTotal reports indicate that the domain was scanned by 93 AV engines, none of which raised a detection; however, the absence of detections does not imply safety, as the content aligns with known impersonation patterns. The brand target is explicitly listed as MetaMask, and the scam type is recorded as “Crypto Scam”. At the time of writing the site is offline, limiting direct forensic analysis of the page content. Defenders should continue to block tcsdshop.com at network perimeter and proxy layers, monitor for re‑registration or resurrection of the domain, and add the IP address 188.114.97.3 to host‑based deny lists.
Threat intelligence feeds should be updated to include the observed page title and the “WE1” certificate fingerprint for correlation with future campaigns. Continued observation of Cloudflare‑hosted infrastructure and related ASN 13335 activity is recommended, as adversaries frequently leverage this provider for fast‑flux or disposable hosting. No further technical artefacts are available beyond the listed indicators.
Data Coverage
Pipeline de resposta a ameaças
Cobertura de listas de bloqueio
10 fontes externas monitoradas · instantâneo de 12/08/2026
10 fontes externas monitoradas Sem correspondência
Análise do VirusTotal
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo