blaydota-doc[.]com
“Xcode — Install with One Command”
Сохранённое наблюдение
Зафиксированное различие заголовков
blaydota-doc.com is an active crypto drainer site designed to steal cryptocurrency wallet credentials and drain assets from unsuspecting victims. This domain masquerades as a legitimate Blizzard Entertainment support page, tricking users into entering sensitive login or wallet information. The threat involves browser-in-the-browser (BITB) attacks or fake login portals that harvest credentials and private keys, enabling immediate crypto theft. This is not a generic phishing attempt—it is a targeted crypto drainer campaign with real financial consequences. PhishDestroy identifies this domain as a confirmed threat based on multiple indicators. VirusTotal security vendors flagged this domain with a detection rate of 1 out of 95 scanners. The domain was registered on May 07, 2026, through NICENIC INTERNATIONAL GROUP CO., LIMITED, a registrar known for bulk domain registrations that are often abused in short-lived malicious campaigns. The site uses a Let’s Encrypt SSL certificate to appear legitimate and resolves to IP address 188.114.96.3, which hosts multiple suspicious domains. If you visited blaydota-doc.com, do not enter any credentials, wallet addresses, or private keys. Immediately disconnect from the internet and scan your device for malware using reputable antivirus software such as Malwarebytes or Windows Defender. Revoke any session tokens or connected wallet permissions granted while on the site. Change passwords for critical accounts, especially those related to cryptocurrency exchanges or wallets. Enable two-factor authentication (2FA) where possible. If you entered cryptocurrency wallet credentials or private keys, transfer remaining funds to a new, secure wallet immediately. Report the domain to your antivirus provider and consider filing a complaint with the FBI IC3 or your local cybercrime unit. Always verify URLs manually and avoid clicking links in unsolicited messages.
Данные сетевой безопасности Registrar context
Процесс реагирования на угрозы
Проверка по блок-листам
Источников: 10 · синхронизировано 10.08.2026
Хронология обнаружения
Сохранённые наблюдения в хронологическом порядке.
-
Доступность
Доступность: впервые отмечено как unknown
993d00c35140 -
Доступность
Доступность: unknown → redirected
d6602a8661f2 -
Доступность
Доступность: redirected → unknown
3652656a49e2 -
Доступность
Доступность: unknown → redirected
1d3408f88465 -
Доступность
Доступность: redirected → unknown
7cebcfd4071c -
Доступность
Доступность: unknown → redirected
1b9ee5c8a1a4 -
Доступность
Доступность: redirected → unknown
ca255b61650a -
Доступность
Доступность: unknown → redirected
01b292461e0a -
Доступность
Доступность: redirected → unknown
d8f7d37d7f95 -
Доступность
Доступность: unknown → redirected
f06e2004c96f
Сохранённый снимок
Аналитика доменов
Технические деталиDNS, имена TLS и временные метки
ICANN OVERSIGHT
Аккредитация и контекст RAA
Аккредитация и контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Технологии
Выявлено технологий с высокой уверенностью: 3
Анализ VirusTotal
Анализ производительности сайта
Google PageSpeed Insights — mobile performance audit of blaydota-doc.com · checked May 15, 2026
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание