dappresolvernode-fix[.]pages[.]dev
Проверка домена dappresolvernode-fix.pages.dev на фишинг и безопасность
“React App”
dappresolvernode-fix.pages.dev — Доступен · доступ ограничен (HTTP 403). Олицетворение бренда: Across; Тип мошенничества: Crypto Drainer. Сводка доказательств: VirusTotal 6/93 (ADMINUSLabs, ChainPatrol, alphaMountain.ai, CyRadar, Fortinet); 4 external blocklist matches; PhishDestroy score 82/100. Регистратор: Cloudflare.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
The domain dappresolvernode-fix.pages.dev was created on 21 February 2026 and is currently listed as offline with an HTTP 403 response. Registry data shows the domain was registered through Cloudflare, Inc., and its authoritative nameservers are glen.ns.cloudflare.com and heidi.ns.cloudflare.com. The host resolves to IP 188.114.96.3, which belongs to AS13335 Cloudflare, Inc. and is geolocated in the United States. TLS is provided by a Google Trust Services certificate issued to the WE1 authority, and the server advertises HSTS and HTTP/3 support.
VirusTotal analysis recorded detections by six of ninety‑three security vendors, indicating malicious activity. The domain appears on five public blocklists and is explicitly blocked by PhishDestroy, ScamSniffer, Polkadot, Enkrypt, and Codeesura. Independent reputation services assign very low scores: Gridinsoft rates the domain 0 / 100, while Scamadviser gives it 41 / 100. The page title returned by the web server is “React App,” and the indicated scam type is a fake airdrop that impersonates the Across brand.
Given the combination of recent creation, low reputation metrics, multiple blocklist listings, vendor detections, and the use of a legitimate‑looking SSL certificate, the infrastructure appears to have been rapidly deployed for a targeted impersonation campaign. Defenders should immediately add the domain and its IP address to deny‑list rules on perimeter firewalls and DNS resolvers, ensure web proxy filters block the host, and monitor for any future re‑registration attempts. Continuous threat‑intel feeds should be consulted for related Across‑themed phishing indicators, and any inbound traffic to the domain should be logged and investigated for credential harvesting or malware delivery attempts. Because the site is presently offline, threat actors may reactivate it, so maintaining the block and monitoring stance is recommended.
Процесс реагирования на угрозы
Статус в публичных блок-листах
Технологии · 3 identified
HTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org 100% уверенностиCloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com 100% уверенностиHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100% уверенностиАнализ VirusTotal
Анализ производительности сайта
Google PageSpeed Insights — mobile performance audit of dappresolvernode-fix.pages.dev · checked Apr 14, 2026
Доказательства и внешние отчеты
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание