rexassrewards[.]blog
“Rexas Finance - User Rewards”
rexassrewards.blog — Контент недоступен. Тип мошенничества: Wallet/seed Phishing. Сводка доказательств: VirusTotal 2 detections (engine total unavailable) (Gridinsoft, SOCRadar); 4 external blocklist matches; PhishDestroy score 82/100. Регистратор: NameSilo.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
Analysis of the domain rexassrewards.blog indicates it was actively used for wallet and seed-phishing targeting users of a platform identified as Rexas Finance, based on the observed page title 'Rexas Finance - User Rewards.' The domain was registered on February 21, 2026, through NameSilo, LLC, and resolved to the IP address 172.67.129.237, hosted on Cloudflare's infrastructure (AS13335) in the United States. Nameservers evelyn.ns.cloudflare.com and rodney.ns.cloudflare.com were configured, a common pattern for phishing sites leveraging Cloudflare's privacy and proxy services to obscure origin servers. At the time of assessment, the domain was offline, with no SSL certificate detected, increasing the likelihood of interception or manipulation of user data in transit.
Detection by security vendors is limited but notable: two of 95 vendors on VirusTotal flagged the domain, while five independent security blocklists, including PhishDestroy, ScamSniffer, Polkadot, Enkrypt, and Codeesura, have listed it. Gridinsoft assigned a trust score of 0/100, reinforcing its classification as malicious infrastructure. The scam type is explicitly categorized as wallet/seed phishing, suggesting the site was designed to harvest cryptocurrency wallet credentials or recovery phrases.
While the exact content and functionality of the site remain unanalyzed, the combination of a rewards-themed page title, absence of encryption, and confirmed phishing classification provides sufficient evidence to treat this domain as a confirmed threat. Defenders should ensure this domain is blocked at DNS, proxy, and endpoint levels, and monitor for related infrastructure using the same registrar, nameservers, or hosting provider. No evidence links this domain to legitimate Rexas Finance operations, and users should be advised to disregard any communications or links referencing this domain.
Данные сетевой безопасности Registrar context
Процесс реагирования на угрозы
Статус в публичных блок-листах
Сохранённый снимок
Аналитика доменов
Технические сведенияDNS, SAN в протоколе SSL, временные метки
ICANN OVERSIGHT
Аккредитация и контекст RAA
Аккредитация и контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Криминалистическая аналитика
Анализ VirusTotal
Архивные доказательства
Доказательства и внешние отчеты
PD-20260107-31964E Recipient: abuse@namesilo.com Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание