Перейти к отчёту о безопасности
Checked 09.08.2026 Ref 94503CA6

MALICIOUS — CRITICAL

Проверка домена celestiafinance.com на фишинг и безопасность

celestiafinance[.]com

The domain celestiafinance.com was flagged as a brand‑impersonation site targeting the blockchain project Celestia.

72/100 evidence score · Critical
VirusTotal
4/95
Blocklists
No stored match
Доступность
Последний известный активный · HTTP 200
Report / Add Evidence Appeal this listing
2026-02-26 01:26 UTCПоследний известный активный · HTTP 200

Do not enter credentials, seed phrases, payment details, or personal information on this domain.

⚠️
Этот домен был отмечен как вредоносный
Механизмы безопасности сообщают об обнаружении: 4. Будьте предельно осторожны — не вводите учетные данные или личную информацию.
Jump to section
Краткий обзор отчёта

celestiafinance.com — Последний известный активный (HTTP 200). Олицетворение бренда: Celestia; Тип мошенничества: Brand Impersonation. Сводка доказательств: VirusTotal 4/95 (ChainPatrol, alphaMountain.ai, Seclookup, SOCRadar); PhishDestroy score 72/100. Регистратор: Dynadot.

Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.

Evidence Analysis

Ref 94503CA6

The domain celestiafinance.com was flagged as a brand‑impersonation site targeting the blockchain project Celestia. Registration data shows the domain was created on 17 October 2025 through Dynadot LLC. DNS resolution points to the Amazon‑owned address 52.40.42.113 (AS16509, United States). The host presents an HTTPS certificate issued by Let’s Encrypt (R12) and serves HTTP 200 responses; the page title returned is “For Sale Page”. Server headers reveal Nginx with OpenResty and HTTP Strict Transport Security (HSTS) enabled.

The domain appears on a single security blocklist and is currently listed as offline by PhishDestroy. Reputation scoring is extremely low, with Gridinsoft assigning a trust score of 0 / 100. VirusTotal analysis shows four of ninety‑five scanners flagged the domain, confirming malicious intent. The authoritative nameservers are launch1.spaceship.net and launch2.spaceship.net.

For defenders, the immediate recommendation is to block the domain and its resolving IP at perimeter defenses, update URL filtering lists, and monitor the associated ASN for any new suspicious registrations. Additional measures include inspecting traffic to the nameserver domains, enforcing TLS inspection to capture any future content, and conducting periodic re‑scans of the IP address, as the hosting provider is a large cloud service that may be reused for other fraudulent activities. Continuous watch on new domains registered by the same registrar that contain the “celestia” keyword is also advised.

Stored source results

Recorded verdicts and infrastructure observations for this domain.

VirusTotal
VirusTotal
4 det.
DNS Security
1/14
ScamAdviser
Scamadviser
61/100
Сертификат TLS
R12
Возраст
10 mo
Зафиксированный статус
Последний известный активный 200
PhishDestroy
DestroyList
В списке
Охват данных13 recorded checks
VirusTotal 4 / 95 URLQuery отчет сохранен — ожидается подробный вердикт PhishStats не проверено OTX no community references CF Radar scan completed URLScan capture сохраненный отчет URLScan verdict Анализ завершён DNS-блокировки 1/14 TLS valid certificate, 77d WHOIS 10 mo old Снимок экрана 2 captures · 2 sources Цепочка перенаправлений не исследовано Scamadviser 61/100
Сигналы безопасности
SA Scamadviser Warnings 61/100
This website does not have many visitors We found many low rated websites on the same server This website has only been registered recently. We could not analyze the content of the site
DNSFilter considers this website safe
Данные сетевой безопасности
DNS Provider Blocks 1 / 14
Quad9 Secure

Процесс реагирования на угрозы

Открытие
Checks
Reports
Доступность
12/14
Угроза устранена
celestiafinance.com обнаружены и помещены в очередь для полного анализа
14.12.2025
URLScan.io Capture
Stored URLScan report with capture artifacts
26.02.2026
URLScan Verdict
Анализ URLScan завершен; этот результат веб-захвата не меняет вердикт об угрозе странице · score 0
29.07.2026
Cloudflare Radar Report
A stored Cloudflare Radar report is available. The report link alone is not a malicious verdict and does not prove that every network field was captured.
Web Archive
Preserved in Wayback Machine — historical evidence archived
14.03.2026
VirusTotal
4/95 recorded on VirusTotal
18.07.2026
Google Safe Browsing
02.03.2026
DNS Security Blocks
Blocked by 1 of 14 checked DNS providers: Quad9 secure
Brand Impersonation
Impersonation of Celestia
Forensic Evidence Collected
Stored evidence from URLScan.io, stored screenshot
26.02.2026
Technical Analysis Recorded
Отчет содержит сохраненные технологии или результаты судебно-медицинской экспертизы.
09.08.2026
Complaint Draft Available
Подача не фиксируется. Вы можете создать проект, просмотреть его и самостоятельно отправить в соответствующий орган.
Опубликовано «DestroyList»
14.12.2025
Monitoring Continues
Домен остается доступным или доступ к нему ограничен; будущие проверки могут обновить это наблюдение.

Статус в публичных блок-листах

Сохранённый снимок

Заголовок страницы
For Sale Page
Impersonates
Argent Celestia
Сертификат TLS
Valid transport encryption · Выдан R12 · valid for 77 days

Аналитика доменов

Домен
URLScan Verdict Анализ завершён score 0 report ↗
Сервер / ASN openresty · AS16509 AMAZON-02, US
Репутация IP abuse score 2/100 3 reports checked 28.07.2026
Регистратор Dynadot US(US)
IP-адрес 52.40.42.113 US
ГеолокацияUS Boardman, US
СетьAS16509 · Amazon.com, Inc.
Обратный поиск IPviewdns.info → rapiddns.io →
РегистрацияСоздано 17.10.2025 (296d)
Elapsed Since First Report 91 days
Что мы учитываем Raw elapsed time since the first stored abuse report. It is not a registrar response-time measurement. Latest observed status: Последний известный активный.
Что содержит каждый отчет Сохраненные записи исходящих отчетов могут ссылаться на доказательства, доступные на данный момент, такие как вердикты поставщиков, регистрационные данные, сведения о хостинге, классификации или снимки экрана. На этой странице не указывается точная доставленная полезная нагрузка, получение, подтверждение или действие получателя.
Статус HTTP200
Технические сведенияDNS, SAN в протоколе SSL, временные метки
Впервые обнаружено14.12.2025
DOM Analysisanalyzed 11.03.2026score 10/1002 brand signals
IoC Extractionscanned 02.08.20260 wallet · 0 Telegram IoCs
Submitted URLhttp://celestiafinance.com/
Серверы имёнlaunch1.spaceship.netlaunch2.spaceship.net
TLS Fingerprint
TLS Observationvalid from 15.02.2026scanned 11.03.2026
TLS SAN Domainswww.celestiafinance.com
Favicon Hash
ICANN OVERSIGHT

Аккредитация и контекст RAA

Registrar accreditation and DNS abuse obligations

For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.

Accreditation is a contract, not a safety certification.

RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.

Accountability draft Ничего не отправляется автоматически.
Технологии · 3 identified
Nginx
Web servers Reverse proxies

High-performance HTTP server and reverse proxy, known for stability and low resource usage.

OpenResty
Web servers

Web platform based on Nginx with LuaJIT for scalable web apps.

HSTS
Безопасность

HTTP Strict Transport Security — forces browsers to use HTTPS connections only.

Detected via Cloudflare Radar · Wappalyzer engine
Пожаловаться на этот домен Предоставьте доказательства и помогите защитить других

Анализ VirusTotal

4 / Поставщики средств безопасности 95 отметили этот домен
View on VT
Last analyzed
ChainPatrol
alphaMountain.ai
Seclookup
SOCRadar

Архивные доказательства

Wayback Machine Snapshot
Исторический снимок доступен для проверки доказательств.
View Archive
Анализ производительности сайта

Google PageSpeed Insights — mobile performance audit of celestiafinance.com · checked Mar 2, 2026

76
Needs Work
Performance
FCP
3.18s
First Contentful Paint
LCP
4.58s
Largest Contentful Paint
CLS
0.058
Cumulative Layout Shift
TBT
0ms
Total Blocking Time
SI
4.03s
Speed Index
Powered by Google PageSpeed Insights · Mobile strategy · Scores: 90-100 Good 50-89 Needs Work 0-49 Poor
Доказательства и внешние отчетыIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
If credentials were compromised, report immediately. Do not engage with recovery scammers.

Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.

Европол
Найдите официальный канал отчетности для вашей страны ЕС
National police directory
Остерегайтесь мошенников, предлагающих услуги по восстановлению данных! Преступники могут снова связаться с жертвами, притворяясь следователями, адвокатами или агентами по восстановлению. Не платите авансовые платежи и не делитесь учетными данными. Узнайте больше о мошенничестве при получении компенсаций →

Сообщите об этом в местные органы власти

Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.

Каталог 97 стран
Черновик по шаблону • помощь AI с формулировками включается только с отдельного согласия. Просмотрите и отправьте его самостоятельно
Вставить этот отчетRead-only HTML widget
HTML · IFRAME

Вставить этот отчет

Разместите эту информацию об угрозах на своём сайте или в блоге

embed.html
<iframe
  src="https://phishdestroy.io/ru/embed/domain/celestiafinance.com"
  title="PhishDestroy threat report for celestiafinance.com"
  width="100%" height="320"
  loading="lazy"
  referrerpolicy="no-referrer"
  sandbox="allow-same-origin allow-popups allow-popups-to-escape-sandbox"
  style="border:0;border-radius:12px;max-width:100%"
></iframe>

Очень искреннее благодарственное письмо

Генератор сатирических черновиков

Получатель
Контекст сборов

Это сатирический черновик. Суммы сборов являются оценочными; мы не утверждаем, что они точно относятся к этому домену.