MALICIOUS — HIGH
audius[.]trade
Analysis on July 22, 2026 indicates that the domain audius.trade was registered on March 22, 2026 through NICENIC INTERNATIONAL GROUP CO., LIMITED.
- VirusTotal
- 4/94
- Blocklists
- No stored match
- Kullanılabilirlik
- İçerik kullanılamıyor · HTTP 502
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
audius.trade — İçerik kullanılamıyor (HTTP 502). Marka kimliğine bürünme: ["solana"]; Dolandırıcılık türü: Crypto Scam. Kanıt özeti: VirusTotal 4/94 (ChainPatrol); PhishDestroy score 65/100. Kayıt kuruluşu: NiceNIC.
Özgün adli kaydı korumak için aşağıdaki ayrıntılı PhishDestroy AI analizi İngilizce bırakılmıştır.
Evidence Analysis
Is audius.trade a Crypto Scam?
Analysis on July 22, 2026 indicates that the domain audius.trade was registered on March 22, 2026 through NICENIC INTERNATIONAL GROUP CO., LIMITED.
Analysis on July 22, 2026 indicates that the domain audius.trade was registered on March 22, 2026 through NICENIC INTERNATIONAL GROUP CO., LIMITED. The domain resolves to the Cloudflare‑owned address 172.67.162.154, which is geolocated to Canada. The authoritative nameservers dayana.ns.cloudflare.com and decker.ns.cloudflare.com confirm that the infrastructure is protected by Cloudflare. No SSL certificate was observed, implying that the site operated over plain HTTP. Service fingerprinting detected a Plesk control panel, PHP runtime, and support for HTTP/3, all typical of a commodity hosting environment.
The only page title retrieved before the site was taken offline reads “Airdrop 3 Artists | Audius”. This title together with the classification “Crypto Scam” and the identification of an “Airdrop Scam” phishing kit suggests that the site was used to lure cryptocurrency‑related giveaways. VirusTotal scans recorded four detections out of ninety‑five submitted security vendors, reinforcing the malicious assessment. The domain is listed on a single external blocklist and has been actively blocked by the PhishDestroy service. Independent scoring from Gridinsoft assigned a trust rating of 0 out of 100, indicating no confidence in the site's legitimacy.
Because the site is currently offline, direct interaction is not possible, but the observed indicators—recent registration, Cloudflare hosting, lack of TLS, low trust score, and multiple vendor detections—are consistent with a newly deployed phishing infrastructure targeting crypto users. Defenders should continue to block the domain at perimeter filters, monitor for any resurrection of the host or related sub‑domains, and add the associated IP address to deny lists. Threat hunters should also query threat‑intel feeds for the “Airdrop Scam” kit to uncover potential campaign overlaps.
Stored source results
Recorded verdicts and infrastructure observations for this domain.
Veri kapsamı12 recorded checks
Ağ Güvenliği İstihbaratı Registrar context
Tehdit Müdahale Pipeline
Genel Engelleme Listesi Durumu
Kaydedilen görüntü
Etki Alanı Analizi
Teknik ayrıntılarDNS, SSL SAN’ları, zaman damgaları
ICANN OVERSIGHT
Akreditasyon ve RAA bağlamı
Akreditasyon ve RAA bağlamı
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Latest Classified Outcome 2026-08-09 03:46:25 UTC
Adli İstihbarat
Teknolojiler · 4 identified
Server-side scripting language designed for web development.
Web infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
VirusTotal Analizi
Site Performans Analizi
Google PageSpeed Insights — mobile performance audit of audius.trade · checked Mar 20, 2026
Kanıtlar ve Dış RaporlarIndependent lookups and source reports
“i got an email saying i got a drop from audius. then it brought me to audius.trade. from there i had to link my metamask wallet to get the drop but then a fake metamask log in appeared i entered my details and they took my ETH”
PD-20260320-2C584F Recipient: nicenic@139.com Victim safety and official reportingImmediate actions and verified reporting channels
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.