schildvaultaris[.]biz
“Schild Vaultaris 2026: Capitalize on Bitcoin ETF Opportunities”
schildvaultaris.biz — Непроверенный. Олицетворение бренда: Bitcoin; Тип мошенничества: Brand Impersonation. Сводка доказательств: VirusTotal 13/91 (ADMINUSLabs, alphaMountain.ai, BitDefender, Chong Lua Dao, CyRadar); 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 89/100. Регистратор: Dynadot.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
On 24 July 2026 investigators examined the domain schildvaultaris.biz, which was created on 6 March 2026 through Dynadot LLC. The site resolves to the Cloudflare edge address 188.114.97.3, belonging to ASN 13335 (Cloudflare, Inc.) and is geolocated to the United States. DNS queries return the Cloudflare authoritative name servers felipe.ns.cloudflare.com and jule.ns.cloudflare.com. The HTTPS service presents a Let’s Encrypt certificate issued by the E7 intermediate, indicating a standard automated certificate rather than a brand‑specific TLS deployment. VirusTotal records show that one out of ninety‑four scanning vendors flagged the domain, confirming at least a minimal detection signal. The domain appears on three public blocklists and is explicitly blocked by PhishDestroy, MetaMask, and SEAL, reinforcing its classification as malicious.
The only publicly visible page title reads 'Schild Vaultaris 2026: Capitalize on Bitcoin ETF Opportunities', and the threat profile lists 'Brand Impersonation' with the target brand identified as Bitcoin. Current HTTP status is reported as offline, suggesting the operator has taken the site down or is temporarily inactive. The available evidence points to a short‑lived infrastructure used to lure cryptocurrency‑interested victims by referencing a Bitcoin ETF narrative. While the page content has not been captured, the combination of a recent registration, Cloudflare front‑end, minimal VirusTotal detection, and inclusion on multiple blocklists provides sufficient confidence to label the domain as a Bitcoin impersonation scam.
Uncertainty remains regarding the specific phishing kit, any credential‑stealing forms, and whether additional sub‑domains are being used. Defenders should add schildvaultaris.biz to network‑level deny lists, monitor the associated IP address 188.114.97.3 for any new hostnames, and enforce URL filtering that blocks known blocklist entries.
Процесс реагирования на угрозы
Статус в публичных блок-листах
Сохранённый снимок
Аналитика доменов
Технические сведенияDNS, SAN в протоколе SSL, временные метки
ICANN OVERSIGHT
Аккредитация и контекст RAA
Аккредитация и контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Анализ VirusTotal
Архивные доказательства
Доказательства и внешние отчеты
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание