drugtestall[.]com
Проверка домена drugtestall.com на фишинг и безопасность
“Best Crypto Wallet for Web3, NFTs and DeFi | Trust Security”
drugtestall.com — Контент недоступен (HTTP 502). Олицетворение бренда: Trust Wallet; Тип мошенничества: Cryptocurrency. Сводка доказательств: VirusTotal 16/91 (ChainPatrol, alphaMountain.ai, BitDefender, CRDF, Emsisoft); URLQuery 1 alert; URLScan malicious verdict; Spamhaus DBL_SPAM; 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 95/100. Регистратор: NameCheap.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
Analysis indicates that the domain drugtestall.com was registered through NameCheap, Inc. on September 15, 2011 and continues to resolve to the IPv4 address 158.94.209.40 via the authoritative name servers dns1.namecheaphosting.com and dns2.namecheaphosting.com. The domain is currently classified as a generic phishing operation with a high risk rating and remains active as of the report date, July 21, 2026. Independent threat intelligence sources have observed the domain on a single security blocklist and it is explicitly blocked by the PhishDestroy service. VirusTotal scanning shows that two of ninety‑five security vendors have flagged the domain, providing limited but corroborating evidence of malicious intent.
The limited detection count suggests that the campaign may be employing a low‑profile hosting arrangement or that the malicious payload has not yet been widely distributed. Defenders should consider adding the IP address 158.94.209.40 to network‑level deny lists and ensure that any outbound connections to the domain are intercepted. Continuous monitoring of the domain’s DNS records is recommended, as changes to the nameserver configuration could indicate an escalation of the campaign.
Correlation with other indicators of compromise, such as email subjects or attachment hashes associated with the same phishing kit, may reveal additional victims. Given the high‑risk designation and the presence on an active blocklist, organizations are advised to treat any traffic to drugtestall.com as malicious and to enforce strict email filtering rules that block URLs pointing to the domain. Ongoing review of threat‑intel feeds for new detections will help maintain situational awareness as the campaign evolves.
Данные сетевой безопасности
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| OpenDNS | drugtestall.com |
phishing | Phishing Block |
Процесс реагирования на угрозы
Статус в публичных блок-листах
Сохранённый снимок
Аналитика доменов
Технические сведенияDNS, SAN в протоколе SSL, временные метки
ICANN OVERSIGHT
Аккредитация и контекст RAA
Аккредитация и контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Анализ VirusTotal
Архивные доказательства
Доказательства и внешние отчеты
PD-20260721-C0D629 Recipient: abuse@namecheap.com Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание