monad[.]yeetcaster[.]xyz
“YeetCaster - Turn Takes into Markets”
monad.yeetcaster.xyz — Контент недоступен. Олицетворение бренда: Monad; Тип мошенничества: Brand Impersonation. Сводка доказательств: VirusTotal 12/93 (ChainPatrol, alphaMountain.ai, BitDefender, CRDF, CyRadar); PhishDestroy score 86/100. Регистратор: Tucows.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
PhishDestroy has identified monad.yeetcaster.xyz as a brand impersonation threat targeting the Monad cryptocurrency project. The domain hosts a fraudulent version of YeetCaster, a platform described as "Turn Takes into Markets," designed to deceive users into connecting their wallets or revealing sensitive information. No specific drainer kit has been publicly named, but the site's functionality strongly suggests a crypto drainer or credential harvesting scheme. The threat level is elevated due to the precise impersonation of Monad's brand and the active targeting of its community.
Technical indicators reveal that the domain was created on June 4, 2025, registered through Tucows Domains Inc., and resolves to IP address 66.33.60.67. It uses a Let's Encrypt SSL certificate (R13) to appear legitimate. VirusTotal data shows 12 out of 95 security vendors flagging the domain as malicious, and it appears on one security blocklist. However, Google Safe Browsing (GSB) status is not explicitly negative, meaning users may not receive browser warnings. These factors combined present a clear risk to Monad users who might be lured by the familiar brand name and yeetcaster concept.
The domain has been taken offline following identification and reporting, reducing immediate danger. However, the underlying infrastructure remains, and similar domains may resurface. Users should remain vigilant and always verify URLs on PhishDestroy before interacting with any Monad-related sites. PhishDestroy recommends avoiding unsolicited links, enabling two-factor authentication, and never sharing private keys or seed phrases. Continued monitoring is advised as the threat actors may pivot to new domains.
Процесс реагирования на угрозы
Статус в публичных блок-листах
Сохранённый снимок
Аналитика доменов
Технические сведенияDNS, SAN в протоколе SSL, временные метки
ICANN OVERSIGHT
Registration: yeetcaster.xyz
Аккредитация и контекст RAA
Аккредитация и контекст RAA
Registrar accreditation and DNS abuse obligations
For the registrable domain yeetcaster.xyz behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Технологии · 2 identified
Cloud platform for frontend deployment, optimized for Next.js.
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
Анализ VirusTotal
Архивные доказательства
Доказательства и внешние отчеты
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание