walletapi[.]exchangeeravitt[.]com
“Eravitt AI Token”
Сводка доказательств
This domain is flagged as a high‑risk crypto drainer that masquerades as a cryptocurrency exchange. The site resolves to 2.57.91.189, an IP owned by Hostinger International Limited in Lithuania, and is served over HTTPS with a Let’s Encrypt certificate. The domain was registered on 24 Mar 2025 via GoDaddy and uses the parking‑service nameservers ns1.dns-parking.com and ns2.dns-parking.com. The page title returned by the HTTP 200 response is “Eravitt AI Token”, indicating an attempt to lure victims with a fabricated token offering. Front‑end assets are delivered through third‑party CDNs including Unpkg, jsDelivr, and Hostinger CDN, and the server supports HTTP/3. The domain appears on one security blocklist and is currently blocked by PhishDestroy. VirusTotal scans show 3 of 91 security vendors flagging the domain, and Gridinsoft assigns a trust score of 0 / 100, reinforcing the malicious assessment. While the exact phishing page layout has not been analysed, the combination of a recently created domain, use of reputable CDN services to host malicious scripts, and the “Fake Exchange” classification suggests an intent to harvest crypto credentials or redirect funds. Defenders should immediately block network access to 2.57.91.189 and to walletapi.exchangeeravitt.com, add the domain to URL filtering and email security rules, and monitor for related subdomains or similar CDN usage patterns. Continuous threat‑intel feeds should be consulted for any emerging indicators, and any internal alerts referencing “Eravitt AI Token” or related transaction attempts should be investigated.
Снимок отправленных доказательств
- Отправлено
- Записи журнала
- 1
- ID дела
PD-20260324-C7F813- Заголовок сохранённой страницы
- Eravitt AI Token
- PDF-файл
- PDF с доказательствами
Правовое основание
Полный текст доказательств
Illegal Activities: Active phishing operation targeting victims
Fraud & Deception: Impersonation of legitimate services
Identity Theft: Collection of credentials under false pretenses
Applicable Laws (Unknown):
International Anti-Cybercrime Regulations
Budapest Convention on Cybercrime
Universal Fraud Prevention Laws
Phishing activities violate international cybercrime conventions and Unknown's domestic fraud laws.
Action Required: This evidence-backed report demonstrates clear violations requiring suspension per your policies. Continued hosting exposes your organization to regulatory scrutiny and potential legal liability.
Data Coverage
Процесс реагирования на угрозы
Проверка по блок-листам
10 внешних источников под наблюдением · снимок от 11.08.2026
10 внешних источников под наблюдением Совпадений нет
Хронология обнаружения
-
Статус домена
Доступен → Недоступен
Сохранённый снимок
Аналитика доменов
Технические деталиDNS, имена TLS и временные метки
ICANN OVERSIGHT
Registration: exchangeeravitt.com
Аккредитация и контекст RAA
Аккредитация и контекст RAA
Registrar accreditation and DNS abuse obligations
For the registrable domain exchangeeravitt.com behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Криминалистическая аналитика
Анализ VirusTotal
Анализ производительности сайта
Google PageSpeed Insights — mobile performance audit of walletapi.exchangeeravitt.com · checked Mar 24, 2026
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание