ray-dium[.]lat
“Raydium Staking”
Сводка доказательств
This domain, ray-dium.lat, operates as a confirmed brand impersonation scam specifically targeting users of the Raydium decentralized exchange. Analysis indicates the site mimics Raydium's legitimate staking interface, presenting a fraudulent "Raydium Staking" portal designed to deceive victims into connecting cryptocurrency wallets. The threat actor likely employs wallet-draining techniques to siphon digital assets once users authorize transactions through the malicious interface, a common tactic in crypto-focused phishing operations.
Infrastructure analysis reveals multiple indicators of malicious intent. The domain was registered on December 11, 2025, through Dynadot LLC, a registrar frequently observed in phishing campaigns. It resolves to the IP address 172.67.159.29, which has been associated with other fraudulent domains. Security vendors have flagged the domain, with VirusTotal reporting 2 detections out of 95 engines. Additionally, the domain appears on two distinct security blocklists, further corroborating its malicious classification. The combination of recent registration, brand impersonation, and limited but confirmed detections suggests a targeted operation with elevated risk.
Users who visited ray-dium.lat or interacted with its content should immediately revoke any wallet permissions granted to the site. All connected wallets should be audited for unauthorized transactions, particularly those involving token approvals or asset transfers. If funds were lost, victims should report the incident to relevant blockchain analytics platforms and law enforcement agencies specializing in cryptocurrency fraud. To prevent future exposure, users are advised to verify domain authenticity through official project channels before connecting wallets or entering sensitive information.
Data Coverage
Данные сетевой безопасности
Процесс реагирования на угрозы
Проверка по блок-листам
10 внешних источников под наблюдением · снимок от 12.08.2026
9 внешних источников под наблюдением Совпадений нет
Хронология обнаружения
-
Cloudflare Radar
Сканирование Cloudflare Radar сохранено · Открыть сканирование
Сохранённый снимок
Аналитика доменов
Технические деталиDNS, имена TLS и временные метки
ICANN OVERSIGHT
Аккредитация и контекст RAA
Аккредитация и контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Анализ VirusTotal
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание