www-poly-allocation[.]xyz
“POLY | Distribution”
www-poly-allocation.xyz — Ошибка сервера (HTTP 502). Олицетворение бренда: MetaMask; Тип мошенничества: Wallet/seed Phishing. Сводка доказательств: VirusTotal 11/93 (ADMINUSLabs, ChainPatrol, alphaMountain.ai, CRDF, CyRadar); Spamhaus DBL_PHISH; 3 external blocklist matches (MetaMask, ScamSniffer, SEAL); PhishDestroy score 83/100. Регистратор: NiceNIC.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
The domain www-poly-allocation.xyz was registered on February 21, 2026 through NiceNIC International Group Co., Limited and resolves to the IP address 104.21.86.118, which is owned by Cloudflare, Inc. (ASN 13335) and located in the United States. DNS resolution uses the Cloudflare nameservers doug.ns.cloudflare.com and pam.ns.cloudflare.com, and the site served HTTP/3 with HSTS enabled. An SSL certificate issued by Google Trust Services (subject WE1) was observed, indicating a valid TLS handshake. The page title returned by the server is "POLY | Distribution," and the site claims to impersonate the MetaMask wallet, a classic example of wallet/seed phishing.
Security analysis on VirusTotal recorded that 11 of 93 scanned vendors flagged the domain as malicious. Independent blocklists, including PhishDestroy, MetaMask’s own blocklist, ScamSniffer, and SEAL, have also listed the domain, and it appears on four additional security blocklists. The Gridinsoft trust score is recorded as 0 out of 100, reinforcing the assessment of high malicious intent. Current monitoring shows the site is offline, but its previous activity suggests a targeted attempt to harvest cryptocurrency wallet credentials.
Uncertainty remains regarding the specific phishing kit or the exact content delivered to victims, as no visual analysis of the landing page is available. Defenders should continue to block the domain at network perimeters, update web filtering and DNS sinkhole rules to include the listed nameservers and IP range, and monitor for any re‑hosted copies that might appear on alternative Cloudflare‑owned IPs. Incident response teams should also advise users of MetaMask to verify URLs carefully and to avoid entering seed phrases on untrusted sites.
Данные сетевой безопасности Registrar context
Процесс реагирования на угрозы
Статус в публичных блок-листах
Сохранённый снимок
Аналитика доменов
Технические сведенияDNS, SAN в протоколе SSL, временные метки
ICANN OVERSIGHT
Аккредитация и контекст RAA
Аккредитация и контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Latest Classified Outcome 2026-08-05 18:38:53 UTC
Технологии · 3 identified
HTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org 100% уверенностиCloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com 100% уверенностиHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100% уверенностиАнализ VirusTotal
Архивные доказательства
Доказательства и внешние отчеты
Повлиял ли на вас этот сайт?
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.
Проверить любой домен
Анализ угроз с использованием сохраненного черного списка, WHOIS, DNS и общедоступных доказательств сканирования.
Сканировать сейчасСообщить о фишинге
Добавляйте подозрительные домены в нашу базу данных угроз — защищайте сообщество
СообщитьПоток оперативных данных об угрозах
Недавние сообщения о фишинге и наблюдаемые изменения доступности
ОтслеживатьБудьте в курсе событий, берегите себя
Отслеживайте актуальные угрозы или оспорьте эту запись, если считаете, что это ложное срабатывание