proposal-ethereal[.]trade
proposal-ethereal.trade — Непроверенный. Тип мошенничества: Crypto Scam. Сводка доказательств: VirusTotal 3/93 (Fortinet, Gridinsoft, SOCRadar); Spamhaus DBL_PHISH; 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 66/100. Регистратор: NiceNIC.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
proposal-ethereal.trade was registered on February 23, 2026 through NiceNIC International Group Co., Limited. The domain resolves to the Cloudflare edge address 172.67.162.172, which is associated with ASN 13335 in the United States. No TLS certificate was observed, indicating the site was served without HTTPS. The only visible HTTP response yielded the page title “Just a moment…”, which provides no functional context. VirusTotal reported three positive detections out of ninety‑three scanned engines, and the domain appears on three public blocklists.
It has been explicitly blocked by PhishDestroy, MetaMask, and SEAL, and its current status is offline. The nameservers in use are donald.ns.cloudflare.com and etta.ns.cloudflare.com. Analysis indicates that the domain is being used for a crypto‑related phishing campaign, consistent with the “Crypto Scam” label in the intelligence. The presence of multiple vendor detections, blocklist listings, and targeted blocking by wallet‑related tools such as MetaMask reinforces the malicious intent.
However, because the site is offline and only the page title is known, the exact phishing payload, credential‑capture mechanism, or targeted cryptocurrency service cannot be confirmed. Defenders should continue to monitor the domain for any re‑activation, ensure that outbound traffic to 172.67.162.172 is logged and, where feasible, blocked at the network perimeter. Existing security solutions that reference the known blocklists should already be denying connections, but administrators should verify that the Cloudflare IP is included in any custom deny lists. Incident response teams should also flag any user reports of unexpected wallet prompts or transaction requests that reference this domain, and educate users that the site lacks a valid SSL certificate and displays only a generic title, which are typical indicators of a fraudulent host.
Данные сетевой безопасности Registrar context
Процесс реагирования на угрозы
Статус в публичных блок-листах
Сохранённый снимок
Аналитика доменов
Технические сведенияDNS, SAN в протоколе SSL, временные метки
ICANN OVERSIGHT
Аккредитация и контекст RAA
Аккредитация и контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Latest Classified Outcome 2026-08-13 12:53:31 UTC
Анализ VirusTotal
Архивные доказательства
Доказательства и внешние отчеты
PD-20260223-317FDD Recipient: abuse@nicenic.net, compliance@icann.org Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание