polymarket1min[.]com
Проверка домена polymarket1min.com на фишинг и безопасность
“polymarket1min”
polymarket1min.com — Контент недоступен (HTTP 502). Сводка доказательств: VirusTotal 6/91 (ChainPatrol, alphaMountain.ai, Chong Lua Dao, CRDF, Forcepoint ThreatSeeker); URLQuery 4 alerts; 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 85/100. Регистратор: Porkbun.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
Analysis of polymarket1min.com confirms its classification as a phishing domain targeting users of the Polymarket prediction platform. The domain, registered on February 21, 2026, through Porkbun LLC, resolved to IP address 188.114.97.3, hosted on Cloudflare's infrastructure (AS13335) in the United States. No SSL certificate was detected, increasing the risk of credential interception or data exposure during user interactions. The page title 'polymarket1min' directly references Polymarket, suggesting an intent to deceive users into believing the site is affiliated with the legitimate platform.
Infrastructure analysis reveals the use of Cloudflare nameservers (jack.ns.cloudflare.com and roxy.ns.cloudflare.com), a common tactic to obscure hosting details and evade takedowns. The domain appears on three security blocklists, including PhishDestroy, MetaMask, and SEAL, indicating prior detection and mitigation efforts. VirusTotal reports flagged the domain by 5 of 95 security vendors, though the specific detection signatures or payloads are not detailed in available intelligence. The domain was taken offline by the time of this report, though its prior activity and registration details remain relevant for historical threat analysis.
Defenders should treat this domain as a confirmed phishing threat, particularly for users of Polymarket or similar crypto-based prediction markets. Network-level blocking of the domain and associated IP (188.114.97.3) is recommended to prevent accidental access. Given the lack of SSL and the domain's offline status, further forensic analysis of cached or archived content may be necessary to determine the exact phishing mechanism employed. Registrar and hosting provider abuse reports should be filed to prevent re-registration or reuse of this infrastructure for similar campaigns.
Данные сетевой безопасности
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Hagezi Threat Feed | polymarket1min.com |
malicious | Sinkholed |
| Quad9 DNS | polymarket1min.com |
malicious | Sinkholed |
| Hagezi Threat Feed | svapi00.polymarket1min.com |
malicious | Sinkholed |
| Quad9 DNS | svapi00.polymarket1min.com |
malicious | Sinkholed |
Процесс реагирования на угрозы
Статус в публичных блок-листах
Сохранённый снимок
Аналитика доменов
Технические сведенияDNS, SAN в протоколе SSL, временные метки
ICANN OVERSIGHT
Аккредитация и контекст RAA
Аккредитация и контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Анализ VirusTotal
Архивные доказательства
Доказательства и внешние отчеты
PD-20260214-89491C Recipient: abuse@porkbun.com Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание