defi3q8d[.]top
“POOL-VIP”
defi3q8d.top — Контент недоступен. Тип мошенничества: Crypto Scam. Сводка доказательств: VirusTotal 6/95 (alphaMountain.ai, Bfore.Ai PreCrime, CyRadar, Fortinet, G-Data); 1 external blocklist match (ScamSniffer); PhishDestroy score 68/100. Регистратор: 域名國際有限公司.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
This report provides a technical analysis of the domain defi3q8d.top, identified as a crypto drainer, as of July 24, 2026. The domain was registered through 域名國際有限公司 and created on July 25, 2025. It currently resolves to the IP address 172.67.129.18, which is located in the United States and is part of the AS13335 Cloudflare, Inc. network. The domain has been taken offline, and its current status is marked as such.
The page title, 'POOL-VIP,' suggests that the site may have been designed to mimic a legitimate cryptocurrency pool or service, though the exact content has not been analyzed. The domain does not have an SSL certificate, which is a common indicator of a low-security or potentially malicious site. Analysis indicates that defi3q8d.top appears on two security blocklists, specifically PhishDestroy and ScamSniffer, further supporting its classification as a crypto drainer. Gridinsoft assigns this domain a trust score of 0 out of 100, indicating a high level of suspicion.
While the domain is currently offline, defenders should remain vigilant and ensure that it is blocked in their network security policies to prevent any potential future reactivation. The nameservers used for this domain are fattouche.ns.cloudflare.com and kay.ns.cloudflare.com, which are managed by Cloudflare, a known hosting and DNS provider. The domain's presence on multiple blocklists and its low trust score should be considered when evaluating the risk it poses to users and networks.
Процесс реагирования на угрозы
Статус в публичных блок-листах
Сохранённый снимок
Аналитика доменов
Технические сведенияDNS, SAN в протоколе SSL, временные метки
ICANN OVERSIGHT
Аккредитация и контекст RAA
Аккредитация и контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Анализ VirusTotal
Доказательства и внешние отчеты
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание