mixquitylabs[.]org
“Steaks & Peaches”
mixquitylabs.org — Непроверенный. Олицетворение бренда: Ethereum; Тип мошенничества: Fake Airdrop. Сводка доказательств: VirusTotal 5/93 (alphaMountain.ai, CyRadar, Fortinet, Kaspersky, SOCRadar); PhishDestroy score 65/100. Регистратор: NiceNIC.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
mixquitylabs.org was registered on February 21, 2026 through NiceNIC International Group Co., Limited. The domain resolves to IP address 104.21.38.30, which is owned by Cloudflare, Inc. (AS13335) and geolocated in the United States. An SSL certificate issued by Google Trust Services under the WE1 root secures the site, indicating a legitimate‑looking HTTPS presence. The page title observed during analysis was "Steaks & Peaches," and the site is listed as impersonating Ethereum to promote a fake airdrop, a classic brand‑impersonation scam.
The domain appears on a single security blocklist and is explicitly blocked by PhishDestroy. Gridinsoft assigned a trust score of 0 out of 100, reflecting extreme suspicion. VirusTotal analysis shows five of ninety‑three security vendors flagged the domain as malicious, reinforcing the perception of malicious intent. Technologically, the site employed Cloudflare services and HTTP/3, which can obscure the true origin of the payload.
The current operational status is offline, but the infrastructure artifacts (nameservers amy.ns.cloudflare.com and garrett.ns.cloudflare.com, IP address, SSL certificate) remain observable and could be reused in future campaigns. Defenders should immediately add mixquitylabs.org and its resolving IP to network blocklists, enforce DNS filtering, and consider requesting Cloudflare to null‑route the domain. Continuous monitoring of the registrar NiceNIC and the associated Cloudflare nameservers is advised, as attackers often provision new domains with similar registration characteristics. Organizations should also educate users about unsolicited Ethereum airdrop offers and advise verification against official Ethereum communication channels.
Данные сетевой безопасности Registrar context
Процесс реагирования на угрозы
Статус в публичных блок-листах
Сохранённый снимок
Аналитика доменов
Технические сведенияDNS, SAN в протоколе SSL, временные метки
ICANN OVERSIGHT
Аккредитация и контекст RAA
Аккредитация и контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Latest Classified Outcome 2026-08-13 03:10:17 UTC
Технологии · 2 identified
Cloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com 100% уверенностиHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100% уверенностиАнализ VirusTotal
Архивные доказательства
Доказательства и внешние отчеты
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание