mints-mythical-market[.]com
“Buy and Sell Fifa Rivals Items | Mythical Market”
mints-mythical-market.com — Контент недоступен. Олицетворение бренда: Google; Тип мошенничества: Crypto Scam. Сводка доказательств: VirusTotal 13/95 (ADMINUSLabs, alphaMountain.ai, BitDefender, CRDF, CyRadar); Spamhaus DBL_PHISH; 1 external blocklist match (ScamSniffer); PhishDestroy score 89/100. Регистратор: Name SRS AB.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
The domain mints-mythical-market.com was registered on November 16, 2025 through the registrar Name SRS AB and is currently taken offline. DNS resolution points to the Cloudflare network (AS13335) with the address 172.64.144.127, a US‑based hosting location that is commonly leveraged for fast‑flux or abuse mitigation. The zone is served by three orderbox‑derived nameservers: fdomain.earth.orderbox-dns.com, fdomain.mars.orderbox-dns.com, and fdomain.mercury.ord, suggesting the use of a third‑party DNS management platform rather than direct registrar control. No TLS certificate is presented, meaning connections are unencrypted and the site cannot provide HTTPS integrity guarantees.
The page title observed during scanning reads "Buy and Sell Fifa Rivals Items | Mythical Market," which does not reference the targeted brand, yet the intelligence set classifies the campaign as a Google brand impersonation and a crypto‑related scam. VirusTotal reports 13 detections out of 95 scanning engines, indicating that a subset of security products flag the domain as malicious. The domain appears on two public blocklists and is explicitly listed by PhishDestroy and ScamSniffer, reinforcing its malicious reputation. Gridinsoft’s trust score is 0 / 100, further confirming a lack of confidence in the site’s legitimacy.
The elevated risk rating reflects the convergence of brand impersonation, crypto‑scam claims, and confirmed detections. Uncertainties remain around the exact phishing kit or payload, as no SSL, visual, or login page details have been captured. Defenders should add the domain to blocklists, monitor the hosting IP for any re‑use, and enforce DNS‑level filtering for the identified nameservers. Continuous re‑scanning is recommended to capture any changes should the site come back online.
Процесс реагирования на угрозы
Статус в публичных блок-листах
Сохранённый снимок
Аналитика доменов
Технические сведенияDNS, SAN в протоколе SSL, временные метки
ICANN OVERSIGHT
Аккредитация и контекст RAA
Аккредитация и контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Анализ VirusTotal
Доказательства и внешние отчеты
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание