web3conn[.]com
Verificação de phishing e segurança de web3conn.com
web3conn.com — Conteúdo indisponível (HTTP 502). Tipo de golpe: Investment Scam. Resumo das evidências: VirusTotal 3/95 (alphaMountain.ai, CyRadar); 3 external blocklist matches (Polkadot, Enkrypt, Codeesura); PhishDestroy score 74/100. Registrador: Ultahost.
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
Analysis of web3conn.com shows a newly registered domain (creation date November 01, 2025) that has been linked to an investment‑type phishing campaign. VirusTotal records indicate that three of ninety‑five security vendors have classified the domain as malicious, and AlienVault OTX references the domain in a single threat‑intelligence pulse. The domain appears on four independent security blocklists and has been explicitly blocked by PhishDestroy, Polkadot, Enkrypt, and Codeesura. Infrastructure data reveals that the domain resolves to the IP address 198.18.1.124 and is hosted without an SSL certificate, meaning all traffic would be unencrypted HTTP.
The authoritative name servers are ns5.asurahosting.com, ns6.asurahosting.com, ns5.my-control-panel.com, and ns6.my-control-panel.com. Registration was performed through Ultahost, Inc., and the Gridinsoft trust score is 0 out of 100, indicating an extremely low reputation. Current monitoring shows the domain is taken offline, but the historical presence on blocklists and the low trust score suggest it may be re‑activated or used in a similar fashion by related actors.
Defenders should ensure that web3conn.com and its resolving IP 198.18.1.124 are denied in outbound and inbound filtering policies, confirm that no residual DNS entries remain cached in internal resolvers, and add the domain to any custom threat‑intel feeds. Continuous observation of Ultahost, Inc. registrations is advised, as the registrar has been associated with other malicious infrastructure. Given the elevated risk rating, security teams should also review any recent user reports of unsolicited investment offers that reference the domain and consider proactive user awareness messaging about potential investment scams.
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Captura armazenada
Inteligência de Domínios
Detalhes técnicosDNS, SANs do SSL, carimbos de data e hora
ICANN OVERSIGHT
Credenciamento e contexto RAA
Credenciamento e contexto RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Análise do VirusTotal
Evidências e relatórios externos
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo