eth-web3[.]vip
“ETH”
Сводка доказательств
The domain eth-web3.vip is identified as a high-risk brand impersonation threat targeting Counter-Strike 2 (CS2) users. Analysis confirms the domain was designed to mimic legitimate CS2 skin gambling platforms, leveraging the ETH cryptocurrency for fraudulent transactions. Current status indicates the domain is offline, though prior activity suggests intent to deceive users into transferring digital assets under false pretenses. Infrastructure analysis reveals the domain was registered on February 24, 2025, through Dominet (HK) Limited and resolved to the IP address 47.239.42.247, hosted on Alibaba (US) Technology Co., Ltd. infrastructure (AS45102). Security vendors flagged the domain in 19 of 95 VirusTotal scans, while it appears on three distinct security blocklists. The absence of an SSL certificate further undermines its legitimacy, as encrypted connections are standard for financial or gambling-related platforms. Additional detection by multiple browser-based security extensions corroborates the malicious classification. Given the domain's current offline status, the immediate threat to end users is mitigated. However, historical indicators suggest potential for re-emergence under similar infrastructure. Organizations and individuals are advised to proactively block the domain and its associated IP (47.239.42.247) at the network level. Users should verify the authenticity of any CS2-related gambling or trading platforms by cross-referencing official brand channels. Cryptocurrency wallet addresses linked to this domain should be treated as compromised and avoided in future transactions. Continuous monitoring of newly registered domains with similar naming patterns (e.g., 'web3', 'eth', or 'cs2') is recommended to preempt further impersonation attempts.
Снимок отправленных доказательств
- Отправлено
- Записи журнала
- 1
- ID дела
PD-20260120-2CF04B- Заголовок сохранённой страницы
- ETH
- PDF-файл
- PDF с доказательствами
Полный текст доказательств
Acceptable Use Policy (AUP): The domain eth-web3.vip is engaged in phishing activities, which is a direct violation of your AUP prohibiting illegal activities, fraud, and deception.
Terms of Service (TOS): The continued operation of this domain constitutes a violation of your TOS, which reserves the right to suspend or terminate services for any activities that breach legal standards or your policies.
Applicable Laws (IN):
Information Technology Act, 2000 (IT Act): Specifically, Section 66D criminalizes cheating by personation using computer resources, which applies to phishing schemes.
Indian Penal Code, 1860 (IPC) - Section 420: This section addresses cheating and dishonestly inducing delivery of property, applicable to the fraudulent activities associated with phishing.
Regulatory Note: Failure to take immediate action against this domain may result in liability under applicable laws and could expose your organization to regulatory scrutiny. Prompt compliance is essential to mitigate potential legal repercussions.
Data Coverage
Данные сетевой безопасности
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DigiCert UltraDNS | eth-web3.vip |
malicious | Sinkholed |
| CIRA Canadian Shield DNS | eth-web3.vip |
malicious | Sinkholed |
| Cloudflare DNS | eth-web3.vip |
malicious | Sinkholed |
| Quad9 DNS | eth-web3.vip |
malicious | Sinkholed |
| DigiCert UltraDNS | vip.eth-web3.vip |
malicious | Sinkholed |
| Quad9 DNS | vip.eth-web3.vip |
malicious | Sinkholed |
| CIRA Canadian Shield DNS | vip.eth-web3.vip |
malicious | Sinkholed |
| Cloudflare DNS | vip.eth-web3.vip |
malicious | Sinkholed |
Процесс реагирования на угрозы
Проверка по блок-листам
10 внешних источников под наблюдением · снимок от 10.08.2026
10 внешних источников под наблюдением Совпадений нет
Хронология обнаружения
-
Статус домена
Доступен → Недоступен
-
Cloudflare Radar
Сканирование Cloudflare Radar сохранено · Открыть сканирование
Сохранённый снимок
Аналитика доменов
Технические деталиDNS, имена TLS и временные метки
ICANN OVERSIGHT
Аккредитация и контекст RAA
Аккредитация и контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Анализ VirusTotal
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание