nebofex[.]com
Проверка домена nebofex.com на фишинг и безопасность
“Nebofex: Elon Musk’s Official Crypto Casino Powered by Blockchain”
nebofex.com — Контент недоступен (HTTP 502). Олицетворение бренда: Ton; Тип мошенничества: Crypto Scam. Сводка доказательств: VT 13/93 (ADMINUSLabs, alphaMountain.ai, BitDefender, CRDF, CyRadar); URLQuery 0; URLScan malicious; GSB no flag; BL 0; PD 94/100. Регистратор: Hello Internet.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
PhishDestroy first observed nebofex.com on Jan 24, 2026. Positive findings were recorded by VirusTotal and URLScan. Evidence score: 94/100.
VirusTotal recorded 13 detections among 93 engines: ADMINUSLabs, alphaMountain.ai, BitDefender, CRDF, CyRadar, Forcepoint ThreatSeeker, Fortinet, G-Data on Feb 25, 2026 at 00:12 UTC. URLScan returned a malicious verdict with score 100 on Mar 27, 2026 at 11:56 UTC. The external blocklist snapshot contained no matches on Aug 7, 2026 at 10:20 UTC. URLQuery recorded no positive detection. Google Safe Browsing returned no flag on Mar 3, 2026 at 04:14 UTC.
HTTP 502 was recorded on Aug 7, 2026 at 01:21 UTC; content was unavailable. Registration records list Hello Internet Corp as the registrar. At collection time, the domain resolved to 2606:4700:3036::ac43:acc9. Collected metadata identifies Ton as the apparent target. Captured page title: “Nebofex: Elon Musk’s Official Crypto Casino Powered by Blockchain”. PhishDestroy classified the observed content as Crypto Scam. DOM analysis completed on Apr 23, 2026 at 03:23 UTC; stored DOM score 15/100. IoC extraction completed on Aug 2, 2026 at 04:16 UTC; stored 0 format-validated wallet addresses and 0 Telegram indicators.
Stored full analysis23.07.2026
Analysis of nebofex.com, registered on February 21 2026 through Hello Internet Corp, shows a short-lived infrastructure that was taken offline before the report date of July 23 2026. The domain resolves to the IPv6 address 2606:4700:3036::ac43:acc9, a Cloudflare edge server identified as AS13335 (Cloudflare, Inc.) located in the United States. Nameserver records point to algin.ns.cloudflare.com and magali.ns.cloudflare.com, confirming the use of Cloudflare’s DNS service. No TLS certificate was observed for the site, indicating that any HTTP traffic would have been unencrypted. The page title retrieved during the brief online period was "Nebofex: Elon Musk’s Official Crypto Casino Powered by Blockchain," which ties the site to a crypto‑focused scam narrative. The content explicitly impersonates the TON brand, matching the declared brand target of "ton" and the broader classification of a crypto scam.
Threat intelligence feeds indicate the domain appears on one security blocklist and was blocked by PhishDestroy. VirusTotal scans reported 13 detections out of 93 security vendors, reinforcing the malicious assessment. The Gridinsoft trust score of 0 / 100 further reflects a lack of legitimacy. The phishing kit identified as "Gambler Scam" aligns with the casino‑themed page title and suggests a template designed to lure cryptocurrency‑interested victims.
Given the absence of an SSL certificate, the reliance on Cloudflare’s infrastructure, and the confirmed detections, defenders should continue to treat nebofex.com as malicious. Network security controls should block traffic to the IPv6 address 2606:4700:3036::ac43:acc9 and to the domain itself. Endpoint and email security solutions should incorporate the domain and its associated indicators into their blocklists, and threat‑intel sharing platforms should be updated with the observed characteristics to aid in rapid detection of any re‑use of the underlying infrastructure.
Процесс реагирования на угрозы
Статус в публичных блок-листах
Сохранённый снимок
Аналитика доменов
Технические сведенияDNS, SAN в протоколе SSL, временные метки
ICANN OVERSIGHT
Аккредитация и контекст RAA
Аккредитация и контекст RAA
ICANN получила деньги. Подотчётность так и не появилась.
Для этой gTLD указанный выше регистратор работает по договору с ICANN. ICANN взимает ежегодные, переменные и транзакционные сборы, связанные с регистрациями, продлениями и трансферами.
Аккредитация: монетизирована. Подотчётность: пожалуйста, проверьте позже.
Затем начинается магия: ICANN пишет RAA §3.18, регистратор расследует злоупотребления внутри собственной клиентской базы, а жертвы бесплатно предоставляют доказательства, пока каждый уровень ждёт, что действовать начнёт кто-то другой. Если благодаря этому жертвы чувствуют себя в большей безопасности — отлично: счёт сделал своё дело.
Анализ VirusTotal
Доказательства и внешние отчеты
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Об этом отчете: nebofex.com
В этом отчете представлены последние сохраненные доказательства, доступные PhishDestroy. Временные метки источника отображаются там, где они доступны; Вердикты о доступности и поставщика могут измениться после сбора.
Захваченный сайт отображал заголовок страницы “Nebofex: Elon Musk’s Official Crypto Casino Powered by Blockchain” и мог выдавать себя за Ton.
Начиная с 07.08.2026, nebofex.com обнаруживался механизмами безопасности 13.
Если вы считаете, что это объявление неточно, подать апелляцию. Чтобы узнать о нашей методологии, посетите Страница часто задаваемых вопросов.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание