changelly[.]asia
“Cryptocurrency Exchange - Crypto & Altcoin Swap Platform with Lowest Fees”
changelly.asia — Контент недоступен (HTTP 502). Олицетворение бренда: Ebay; Тип мошенничества: Wallet/seed Phishing. Сводка доказательств: VirusTotal 13/95 (ADMINUSLabs, alphaMountain.ai, BitDefender, CyRadar, ESET); 2 external blocklist matches (ScamSniffer, Enkrypt); PhishDestroy score 89/100. Регистратор: Porkbun.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
Analysis as of July 23 2026 indicates that the domain changelly.asia, registered through Porkbun LLC on 10 October 2025, is currently offline but was previously used for a wallet/seed phishing campaign impersonating eBay. The site presented a page titled “Cryptocurrency Exchange – Crypto & Altcoin Swap Platform with Lowest Fees,” suggesting a cryptocurrency lure. DNS resolution points to IP 62.60.226.213 located in Germany and associated with AS214351 FEMO IT SOLUTIONS LIMITED. No TLS certificate was observed, meaning communications were unencrypted.
The domain is listed on three public blocklists—PhishDestroy, ScamSniffer, and Enkrypt—and appears on three additional security blocklists, reinforcing its malicious reputation. VirusTotal records show that 13 of 95 scanned security vendors flagged the domain, providing further corroboration. Reputation services assign low trust scores: Scamadviser rates the domain 35/100 and Gridinsoft rates it 0/100. The authoritative nameservers are curitiba.ns.porkbun.com, fortaleza.ns.porkbun.com, maceio.ns.porkbun.com, and salvador., all hosted by the registrar’s infrastructure.
The combination of a high‑risk classification, brand impersonation of eBay, and the wallet/seed phishing objective suggests credential or private‑key harvesting attempts. Uncertainty remains around the current activity level because the site is offline; however, the infrastructure—IP address and nameserver configuration—may be reused for future campaigns. Defenders should block DNS resolution to 62.60.226.213, add the domain and its nameservers to URL filtering and email security policies, monitor for any newly registered domains using the same registrar and similar naming patterns, and enforce multi‑factor authentication for eBay accounts to mitigate credential compromise. Continuous monitoring of the listed blocklists and periodic re‑scanning of the domain, should it reappear, are recommended.
Сигналы безопасности
Процесс реагирования на угрозы
Статус в публичных блок-листах
Сохранённый снимок
Аналитика доменов
Технические сведенияDNS, SAN в протоколе SSL, временные метки
ICANN OVERSIGHT
Аккредитация и контекст RAA
Аккредитация и контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Анализ VirusTotal
Доказательства и внешние отчеты
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание