Notification and current-status evidence
The sent-report ledger records the first outgoing report at .
The recorded recipient is abuse@estoxy.com.
The latest stored availability evidence still shows the domain reachable; 2 months has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
cryptoinvestment[.]cc
“Qf Remedy Ledger - Next Generation Crypto Wallet”
cryptoinvestment.cc — Непроверенный. Олицетворение бренда: Ledger; Тип мошенничества: Brand Impersonation. Сводка доказательств: VirusTotal 8/91 (alphaMountain.ai, CRDF, CyRadar, Forcepoint ThreatSeeker, Fortinet); URLQuery 1 alert; Spamhaus DBL_SPAM; PhishDestroy score 83/100. Регистратор: Hostinger.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
This domain, cryptoinvestment.cc, presents a high-confidence brand impersonation threat targeting Ledger crypto wallet users. Analysis indicates the site masquerades as a legitimate hardware wallet provider, likely distributing malicious software designed to drain cryptocurrency from connected wallets. The page title, 'Qf Remedy Ledger - Next Generation Crypto Wallet,' directly references Ledger while introducing suspicious branding elements that deviate from official Ledger communications, suggesting an attempt to deceive users into installing compromised wallet applications or revealing recovery phrases. Infrastructure analysis reveals multiple high-risk indicators. The domain was registered on January 27, 2025, through HOSTINGER operations, UAB, and resolves to IP address 37.49.229.75. Security vendors on VirusTotal flagged the domain at 8/95, while it appears on two independent security blocklists. Detected technologies include PHP, Tailwind CSS, LiteSpeed, Alpine.js, Unpkg, and jsDelivr, with HTTP/3 support and a Let's Encrypt SSL certificate. The combination of recent registration, hosting provider, and front-end frameworks aligns with patterns observed in crypto drainer distribution campaigns. Users who visited cryptoinvestment.cc or interacted with its content should immediately revoke any wallet connections and cease all transactions. Any software downloaded from this domain should be considered compromised and removed from devices. Wallet recovery phrases or private keys entered on this site must be treated as exposed, requiring immediate migration of funds to new, secure wallets. Monitoring for unauthorized transactions and implementing additional authentication layers on crypto accounts is strongly recommended. Organizations should update blocklists to include this domain and its associated IP address to prevent further exposure.
Данные сетевой безопасности
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DNS4EU | cryptoinvestment.cc |
malicious | Sinkholed |
Процесс реагирования на угрозы
Статус в публичных блок-листах
Технологии · 7 identified
JSDelivr is a free public CDN for open-source projects. It can serve web files directly from the npm registry and GitHub repositories without any configuration.
www.jsdelivr.com 100% уверенностиHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100% уверенностиАнализ VirusTotal
Анализ производительности сайта
Google PageSpeed Insights — mobile performance audit of cryptoinvestment.cc · checked Jun 26, 2026
Анализ конфигурации сайта
Доказательства и внешние отчеты
PD-20260603-827279 Recipient: abuse@estoxy.com Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание