raydem[.]cc
Проверка домена raydem.cc на фишинг и безопасность
“Website Created”
raydem.cc — Контент недоступен (HTTP 502). Олицетворение бренда: Celer; Тип мошенничества: Brand Impersonation. Сводка доказательств: VirusTotal 5/91 (alphaMountain.ai, CRDF, Forcepoint ThreatSeeker, Gridinsoft, SOCRadar); PhishDestroy score 65/100. Регистратор: NiceNIC.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
Analysis of the domain raydem.cc indicates it was actively involved in brand impersonation targeting Celer, a known blockchain interoperability platform. The domain was registered on August 23, 2025, through NiceNIC International Group Co., Limited, and resolved to the IP address 172.67.213.219, hosted on Cloudflare's infrastructure (AS13335) in the United States. No SSL certificate was detected, which is atypical for legitimate services and may indicate an attempt to evade encrypted traffic inspection or reduce operational costs. The domain's page title was recorded as 'Website Created,' a generic placeholder that provides limited insight into the specific content hosted. However, the scam type was explicitly classified as brand impersonation, aligning with the identified target, Celer.
At the time of reporting, the domain was flagged by three of 95 security vendors on VirusTotal, though this detection rate alone does not confirm the full scope of malicious activity. It also appeared on one security blocklist, further supporting its classification as suspicious infrastructure. Infrastructure analysis reveals the use of Cloudflare nameservers (athena.ns.cloudflare.com and quinton.ns.cloudflare.com), a common tactic to obscure hosting origins and enhance resilience against takedowns. The domain was blocked by PhishDestroy and assigned a Gridinsoft trust score of 0/100, reinforcing its high-risk status. As of July 24, 2026, raydem.cc is offline, though defenders should monitor for potential reactivation or migration to new domains.
Organizations are advised to review logs for connections to 172.67.213.219 or raydem.cc, particularly from users interacting with Celer-related services. Proactive blocking of the domain and IP at the network level is recommended to mitigate residual risk. Given the use of Cloudflare, defenders should also assess whether additional domains resolving to the same IP or nameservers exhibit similar patterns.
Данные сетевой безопасности Registrar context
Процесс реагирования на угрозы
Статус в публичных блок-листах
Latest Classified Outcome 2026-08-08 02:38:56 UTC
Анализ VirusTotal
Доказательства и внешние отчеты
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание