defiluanhem[.]com
“DeFi Trading”
Сводка доказательств
The domain defiluanhem.com was registered on February 21, 2026 and is currently offline. DNS resolution points to IP address 104.21.80.1, which belongs to Cloudflare, Inc. (AS13335) and is geolocated in the United States. The site presented a page title of "DeFi Trading," indicating an attempt to lure victims into a decentralized finance context. Security telemetry shows the domain is listed on two independent blocklists and has been actively blocked by both PhishDestroy and ScamSniffer.
The Gridinsoft trust score is 0 out of 100, reflecting a complete lack of confidence in the site’s legitimacy. VirusTotal analysis reports three of ninety‑three scanning engines flagging the domain, reinforcing the suspicion of malicious activity. The SSL certificate is identified as WE1, which suggests a weak or improperly issued certificate, a common characteristic of fraudulent infrastructure. The classification as a "crypto drainer" aligns with the observed page title and the broader threat landscape targeting cryptocurrency users.
While the exact phishing kit or the specific DeFi platform being spoofed is not disclosed, the convergence of blocklist presence, low trust scoring, weak TLS, and multiple vendor detections provides strong evidence of a crypto‑related scam. Defenders should continue to block the domain at network perimeter devices, update threat intelligence feeds with the indicator set, and monitor for any re‑registration attempts. Additional investigation of the associated IP range for other malicious hosts is advised, as Cloudflare services are often leveraged to obscure attacker infrastructure.
Data Coverage
Процесс реагирования на угрозы
Проверка по блок-листам
10 внешних источников под наблюдением · снимок от 10.08.2026
9 внешних источников под наблюдением Совпадений нет
Сообщения сообщества
Сообщил 1 участник сообщества; впервые замечено 06.08.2025
- Сохранённые сообщения
- 1
- Уникальные URL
- 1
Данные сообщества
1 сообщение сообщества
КатегорияPHISHING
The PhishDestroy system has identified this domain as a phishing threat, flagged both by our internal parser and reported by users. We also cross-reference with public databases and other antivirus systems.
Криминалистическая аналитика
Анализ VirusTotal
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание