VirusTotal
8 / 89
“5MTBot — Automated Polymarket Bot for 5-Minute Crypto Rounds”
The sent-report ledger records the first outgoing report at .
The recorded recipient is abuse@spaceship.com.
The latest stored availability evidence still shows the domain reachable; 28 days has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
5mtbot.com — Bilinen son aktif (HTTP 301). Dolandırıcılık türü: Impersonation. Kanıt özeti: VirusTotal 8/89 (ChainPatrol, CRDF, Forcepoint ThreatSeeker, Gridinsoft, Kaspersky); 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 95/100. Kayıt kuruluşu: Spaceship.
Özgün adli kaydı korumak için aşağıdaki ayrıntılı PhishDestroy AI analizi İngilizce bırakılmıştır.
8 / 89
checked — no detections recorded
Bildir3 community references
Bildirprovider verdict: clean
Bildirsaklanan rapor
Bildir Analiz tamamlandı
Bildir80/100
BildirChecked; no threat flag recorded
BildirStored evidence for 5mtbot.com: VirusTotal recorded 5 detections among 89 scanners on 2026-09-19. That ratio reproduces the stored check in its original units and is not converted into another measure. MetaMask and SEAL appear as named external blocklist observations for 5mtbot.com. Each item in this report remains at the scope supplied by its dated source record.
VirusTotal records 5 detections among 89 scanners in the stored snapshot dated 2026-09-19. The numerator describes scanners that produced detections, while the denominator describes scanners included in that check. The reverse order would materially alter the stored result. The VirusTotal snapshot dated 2026-09-19 supplies no common rationale covering the included scanners, and this report adds none. A later VirusTotal snapshot may contain different values, so any comparison should preserve the exact ratio and date of each snapshot.
MetaMask and SEAL are recorded as named external blocklist observations for 5mtbot.com in the snapshot dated 2026-09-20. The stored MetaMask and SEAL blocklist records supply names and entries, but they supply no shared method or common rationale. PhishDestroy’s catalogue also contains 5mtbot.com as a publisher record. That PhishDestroy record is counted separately from the MetaMask and SEAL external blocklist observations. This separation keeps the origin of every entry visible and prevents a single stored item from being counted again under another source label.
The record first observed 5mtbot.com on 2026-09-13. The MetaMask and SEAL blocklist snapshot is dated 2026-09-20 and remains a separate event in the stored timeline. A stored HTTP status 200 was observed for 5mtbot.com on 2026-09-20. The HTTP status 200 dated 2026-09-20 records a single response for later comparison. The registration date is separately recorded as 2026-07-30. A URLScan reference was stored on 2026-09-14 as a dated artifact for review. Each timestamp qualifies only the adjacent observation in this timeline. Later collection results should be compared with these dated values without replacing the earlier snapshot.
For 5mtbot.com, the registrar field records Spaceship, Inc.; this is kept as an exact source value. The source stores 188.114.97.3 as the observed address in this record. The registration date for 5mtbot.com is recorded as 2026-07-30. The SSL issuer is recorded as Google Trust Services / WE1 in the snapshot dated 2026-09-13. The stored ASN observation records 13335 and Cloudflare, Inc. in this record. The observed server header is recorded as cloudflare in this record. These fields preserve registration, network, and certificate context stored in this record. The report preserves each label and number as a separate source value instead of combining them into an invented aggregate. Keeping the fields separate leaves every infrastructure value traceable to the record that supplied it.
The 5mtbot.com record states that VirusTotal recorded 5 detections among 89 scanners on 2026-09-19. MetaMask and SEAL remain named blocklist observations from the snapshot dated 2026-09-20. PhishDestroy remains a separate publisher catalogue entry in the stored record. For 5mtbot.com, the registrar field records Spaceship, Inc.; this remains separate from the other source fields. The observed address field in this record contains 188.114.97.3. The supported conclusion is bounded to the exact stored observations for 5mtbot.com. Any statement beyond those source values would require additional dated material.
Avoid submitting sensitive information to 5mtbot.com during review. Use a known service address obtained separately from this report for any necessary access. Defenders can retain 5mtbot.com as an exact indicator and preserve relevant DNS, proxy, and endpoint records. Compare later VirusTotal snapshots and MetaMask and SEAL blocklist records with the dated values above instead of replacing them. Keep each later observation with its source date so changes remain visible during follow-up review. If a defensive rule is needed, keep its scope to 5mtbot.com. The stored record does not justify extending that rule to 188.114.97.3 or to other infrastructure records.
Full extracted values, their blockchain and collection source. An address found in page content does not establish who controls it.
0x06dc51826bc524d9a83770e7de9dd7e005b04524Format validated · Domain analysis0x297200dfadee7d8daeb422faf0f62c238b37c110Format validated · Domain analysis0x388537259dc9e693c1c9b96fdf07a63f6b7aca77Format validated · Domain analysis0x6fd089a1556cdda1ad5efef08f997a03c7c0a85bFormat validated · Domain analysis0x765550c1f0af33254a2ac826710d33a4410c1fa8Format validated · Domain analysis0x952786297c560ebe88de2bac6ccf7cbcf531f108Format validated · Domain analysis0xc02acd7017071c895ac0a7ca923f14584beb10f8Format validated · Domain analysis0xc07c34a7f39f998cc63c6bac977a6ddbcfbdc4b7Format validated · Domain analysis0xf70eb753810c0ccea22a6948ebc3a541f04981dfFormat validated · Domain analysis0xfd9b5aceb381ab40b8a34a87bc5f2db5239f6eeaFormat validated · Domain analysisIoC extraction recorded 2026-09-13 04:00:08 UTC
Bu ana bilgisayar için saklanmış tarayıcı-karşı-tarayıcı gözlemleri ile Keitaro tarzı trafik dağıtım sistemleri için gerçek zamanlı parmak izi kontrolü.
Tarayıcı notu: redirect: raw=redirect_301; http=301; via=https_proxy; location=https://5mtbot.xyz
Edge-IP itibarı bu etki alanıyla ilişkilendirilmez.
gina.ns.cloudflare.comharley.ns.cloudflare.comLocation describes the IP network.
a5b06adcbc983c45ced93387add93a2d4a6367feecc651ac29bb445648212bd6Saved certificate metadata. Certificate dates without a timezone are shown as stored. Transport encryption does not establish that the site is trustworthy.
Google PageSpeed Insights — mobile performance audit of 5mtbot.com · checked Sep 13, 2026
Files, paths and sitemap entries retained by the collector.
/robots.txt
/sitemap.xml
Type: urlset · 9 URL entries
https://5mtbot.com/https://5mtbot.com/bloghttps://5mtbot.com/blog/fee-update-october-2026https://5mtbot.com/blog/what-5mtbot-tradeshttps://5mtbot.com/blog/constellation-strategyhttps://5mtbot.com/blog/simple-and-advanced-strategyhttps://5mtbot.com/blog/settings-and-controlshttps://5mtbot.com/blog/how-trades-resolvehttps://5mtbot.com/privacy188.114.97.3. 13 recorded events. These records describe collected evidence, outgoing notifications and publication; they do not confirm a complete investigation or a takedown.
We scan suspicious URLs, inspect public results and send evidence through the appropriate abuse-reporting channels. The dated events above show what is recorded for this domain. The directory below explains the wider workflow.
Capture the rendered page, requests and visible infrastructure.
Compare the available engine results and retain the analysis timestamp.
Check whether Google currently lists the URL as unsafe.
Inspect a public scan and its recorded network and classification data.
Look for indicator references and related community intelligence.
Compare archived captures and preserve historical context.
Look for matching indicators and associated threat records.
Inspect certificate records and related hostnames.
Compare security resolver responses and record observed blocking.
Inspect the public DNS, TLS, HTTP and technology surface.
Security services used for scanning, reputation checks and reporting are listed below. A service being listed is not evidence that it received, accepted or acted on this particular domain. Recorded submissions appear in the notification history above.
PD-20260912-40F949 Recipient: abuse@spaceship.com Policy Violations: Illegal Activities: Active phishing operation targeting victims Fraud & Deception: Impersonation of legitimate services Identity Theft: Collection of credentials under false pretenses Applicable Laws (Unknown): International Anti-Cybercrime Regulations Budapest Convention on Cybercrime Universal Fraud Prevention Laws Phishing activities violate international cybercrime conventions and Unknown's domestic fraud laws. Action Required: This evidence-backed report demonstrates clear violations requiring suspension per your policies. Continued hosting exposes your organization to regulatory scrutiny and potential legal liability.
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.
Template-based draft · optional AI wording assistance requires separate consent
Saklanan engelleme listesi, WHOIS, DNS ve genel tarama kanıtlarını kullanarak tehdit analizi
Şimdi TaraŞüpheli alan adlarını tehdit veritabanımıza bildirin — topluluğu koruyun
BildirSon kimlik avı raporları ve gözlemlenen kullanılabilirlik değişiklikleri
İzleCanlı tehditleri izleyin veya bunun yanlış bir uyarı olduğunu düşünüyorsanız bu kayda itiraz edin