vzcxiw[.]com
“EcoSeed”
vzcxiw.com — Não verificado. Tipo de golpe: Fake Airdrop. Resumo das evidências: VirusTotal 2/91 (SOCRadar, URLQuery); URLQuery 2 det.; CF Radar malicious; PhishDestroy score 60/100. Registrador: Hefei Juming Network T….
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
PhishDestroy identifies www.vzcxiw.com as an active cryptocurrency wallet drainer site under active phishing investigation. The domain was created on May 10, 2024, and is currently resolving to IP address 108.138.7.45. VirusTotal shows zero detections (2/95 engines) despite confirmed malicious payload delivery to crypto wallet users. The site employs a fraudulent SSL certificate issued by Amazon, creating false trust signals while facilitating credential harvesting and unauthorized transaction approvals. No specific brand impersonation or drainer kit signature has been released publicly at this stage of analysis. This domain exhibits multiple high-risk technical indicators consistent with active phishing infrastructure. VirusTotal detection rate remains at 2/95 despite confirmed malicious activity, indicating either zero-day indicators or obfuscation techniques bypassing current detection. The domain is registered through Hefei Juming Network Technology Co., Ltd., a registrar known for accommodating high-risk registrations. Creation date May 10, 2024, suggests recent deployment as part of coordinated phishing campaigns. Google Safe Browsing (GSB) status remains unflagged, and the domain has not yet appeared on major blocklists despite active malicious operations. The IP address 108.138.7.45 hosts multiple suspicious domains, increasing threat confidence. Current status remains active with confirmed malicious operations targeting cryptocurrency users. PhishDestroy continues monitoring for additional indicators and has flagged the domain for immediate browser-based blocking. The zero detection rate on VirusTotal represents a significant risk as traditional security tools remain unaware of this threat. Users should avoid this domain entirely and report any interactions to their security teams. Remaining risk is assessed as HIGH due to undetected status, recent deployment, and active malicious operations. Immediate blocking at network level is recommended while the investigation continues.
Inteligência de segurança de rede
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Captura armazenada
Inteligência de Domínios
Detalhes técnicosDNS, SANs do SSL, carimbos de data e hora
ICANN OVERSIGHT
Credenciamento e contexto RAA
Credenciamento e contexto RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Tecnologias · 3 identified
Cloud computing platform offering compute, storage, and networking services.
High-performance HTTP server and reverse proxy, known for stability and low resource usage.
Amazon Web Services CDN for low-latency content delivery.
Análise do VirusTotal
Evidências e relatórios externos
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo