MALICIOUS — CRITICAL
onchaina15[.]com
The domain onchaina15.com was registered on April 17, 2026 through Gname.com Pte.
- VirusTotal
- 14/91
- Blocklists
- 2 · MetaMask, SEAL
- Доступность
- Последний известный активный · HTTP 200
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
onchaina15.com — Последний известный активный (HTTP 200). Сводка доказательств: VirusTotal 14/91 (ADMINUSLabs, alphaMountain.ai, BitDefender, Chong Lua Dao, CRDF); 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 100/100. Регистратор: Gname.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
Evidence Analysis
The domain onchaina15.com was registered on April 17, 2026 through Gname.com Pte. Ltd. and is currently resolved to the IP address 188.114.96.3, which belongs to Cloudflare, Inc. in Canada. The authoritative nameservers are gannon.ns.cloudflare.com and khloe.ns.cloudflare.com, indicating that the domain is hosted behind Cloudflare's reverse‑proxy service. The site returns HTTP status code 200 and presents a page titled “Onchain”.
Infrastructure analysis shows that the TLS certificate is issued by Google Trust Services under the WE1 certificate authority, providing a valid chain of trust but offering no indication of the underlying content. The domain appears on three independent security blocklists and is explicitly blocked by PhishDestroy, MetaMask, and SEAL, all of which classify it as a phishing resource. Its presence on these lists aligns with the generic_phishing threat type assigned to the domain.
VirusTotal scans have flagged the domain in 2 out of 95 security vendor engines, and Gridinsoft assigns a trust score of 0 out of 100, reflecting a high likelihood of malicious intent. AlienVault OTX reports the domain in a single threat‑intelligence pulse, further corroborating its association with phishing campaigns. Despite the low detection rate on VirusTotal, the convergence of multiple independent indicators strengthens the risk assessment.
Uncertainty remains regarding the specific payload or credential‑harvesting mechanisms employed, as no malware hashes or URLs have been publicly released. Defenders should treat onchaina15.com as a high‑risk phishing host. Recommended actions include adding the domain to inbound and outbound firewall deny lists, updating URL filtering policies, and monitoring for any authentication attempts directed at the site. Continuous observation of its DNS resolution and blocklist status is advised, as the domain remains active.
Охват данных12 recorded checks
Процесс реагирования на угрозы
Статус в публичных блок-листах
Аналитика доменов
Технические сведенияDNS, SAN в протоколе SSL, временные метки
ICANN OVERSIGHT
Аккредитация и контекст RAA
Аккредитация и контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Анализ VirusTotal
Анализ производительности сайта
Google PageSpeed Insights — mobile performance audit of onchaina15.com · checked Apr 18, 2026
Доказательства и внешние отчетыIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.