app-paal[.]co
“app-paal.co”
app-paal.co — Контент недоступен (HTTP 502). Сводка доказательств: VirusTotal 2/95 (alphaMountain.ai, Fortinet); 2 external blocklist matches (ScamSniffer, Enkrypt); PhishDestroy score 71/100. Регистратор: OwnRegistrar.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
This domain, app-paal.co, is flagged as a high-risk phishing site specializing in crypto wallet drainer attacks. Analysis indicates the infrastructure is designed to mimic legitimate wallet interfaces, tricking users into connecting their wallets to malicious smart contracts. No specific brand impersonation is evident, but the site employs generic wallet-themed lures to deploy drainer scripts targeting Ethereum and other EVM-compatible chains. The absence of a recognized drainer kit signature suggests custom or obfuscated malicious code. Infrastructure analysis reveals critical technical indicators: the domain was registered on August 27, 2024, through OwnRegistrar, Inc., and resolves to the IP address 198.18.0.99. Security vendor detections on VirusTotal stand at 2 out of 95, while the domain appears on three security blocklists. Notably, the site lacks an SSL certificate, a red flag for user data interception. Google Safe Browsing currently does not list the domain, but independent security tools have already blocked it due to confirmed malicious activity. As of the latest assessment, app-paal.co remains active and continues to pose a significant risk to users. The domain’s recent creation, combined with its rapid inclusion on multiple blocklists, suggests a deliberate and ongoing campaign. Users are advised to avoid interacting with the site, revoke any connected wallet permissions, and monitor accounts for unauthorized transactions. Organizations should update firewall rules and endpoint protections to block the domain and its associated IP address. The lack of SSL and minimal vendor detections highlight the need for layered security measures, including real-time threat intelligence feeds and user education on recognizing crypto-themed phishing attempts.
Сигналы безопасности
Процесс реагирования на угрозы
Статус в публичных блок-листах
Анализ VirusTotal
Доказательства и внешние отчеты
“CultDrainer”
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание