vexilo-naren[.]com
“Vexilo Naren™ - KI-Trading Deutschland 2026”
vexilo-naren.com — Conteúdo indisponível (HTTP 502). Representação da marca: Binance; Tipo de golpe: Brand Impersonation. Resumo das evidências: VirusTotal 12/95 (ADMINUSLabs, alphaMountain.ai, BitDefender, CRDF, CyRadar); PhishDestroy score 86/100. Registrador: REALTIME REGISTER.
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
The domain vexilo-naren.com was registered on February 21, 2026 through REALTIME REGISTER B.V. and is currently taken offline. DNS resolution points to IP address 104.21.76.126, which belongs to AS13335 Cloudflare, Inc. and is geolocated in the United States. Both authoritative nameservers, charles.ns.cloudflare.com and jacqueline.ns.cloudflare.com, are Cloudflare‑operated, indicating the site leveraged the provider's CDN and DDoS mitigation services. No SSL certificate is presented for the domain, suggesting that HTTPS was either not configured or was removed prior to takedown.
The page title observed during the brief window of activity was "Vexilo Naren™ - KI‑Trading Deutschland 2026," a title that does not reference the targeted brand but is consistent with a fraudulent front‑end. The threat classification is brand impersonation, specifically targeting the cryptocurrency exchange Binance, as indicated by the intelligence tag "Impersonates: binance" and the declared scam type. Reputation scoring is extremely low, with Gridinsoft assigning a trust score of 0 out of 100. The domain appears on three security blocklists, including PhishDestroy, MetaMask, and SEAL, and VirusTotal recorded 12 positive detections out of 95 scanners, reinforcing the malicious assessment.
Despite the offline status, the infrastructure—Cloudflare edge IP, lack of TLS, and the use of a generic registrar—mirrors common patterns employed by actors seeking to host phishing or credential‑harvesting pages. Defenders should immediately add vexilo-naren.com to URL filtering and DNS blocklists, monitor the associated Cloudflare IP for any resurgence of malicious content, and extend brand protection measures for Binance to capture similar impersonation attempts. Continuous observation of newly registered domains using the same registrar or nameserver pattern is recommended to pre‑empt future campaigns.
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Captura armazenada
Inteligência de Domínios
Detalhes técnicosDNS, SANs do SSL, carimbos de data e hora
ICANN OVERSIGHT
Credenciamento e contexto RAA
Credenciamento e contexto RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Análise do VirusTotal
Evidências e relatórios externos
PD-20260119-90954E Recipient: rtr-security-threats@realtimeregister.com Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo