cab[.]alveonltd[.]com
Kanıt özeti
PhishDestroy identifies cab.alveonltd.com as an active crypto drainer impersonating Alveon Ltd, a legitimate entity in the digital asset space. This malicious domain leverages deceptive branding to trick users into connecting their wallets or entering credentials, risking irreversible cryptocurrency losses. The threat actors behind this campaign use social engineering tactics—such as fake giveaways or fraudulent investment opportunities—to lure victims to the site. Once accessed, the domain executes JavaScript-based wallet drainers or phishing forms to siphon funds directly from connected wallets or trick users into revealing private keys or seed phrases. Given its active status and lack of current detections, the risk of compromise remains high for unsuspecting visitors. This domain was flagged through PhishDestroy’s threat intelligence pipeline after analysis of its infrastructure and behavior. The domain resolves to IP 188.114.96.3 and operates under a Let’s Encrypt SSL certificate, which may lend it an air of legitimacy. Notably, it shows 0 detections on VirusTotal out of 95 engines scanned, indicating a low signature-based detection rate. The domain was registered on March 3, 2026, through TUCOWS.COM, CO., a registrar that has historically been used in both legitimate and malicious deployments. While no active blocklist entries have been identified yet, its recent creation and clean reputation suggest it is a newly deployed threat designed to evade early detection. Users who have visited cab.alveonltd.com should immediately disconnect any connected wallets from the site, revoke any unintended token approvals via blockchain explorers like Etherscan or BscScan, and scan their devices for malware. Do not interact with any prompts or forms on the domain, and avoid re-visiting the link. Report this domain to PhishDestroy and your organization’s SOC for further analysis. If you entered credentials or wallet information, assume compromise and transfer remaining assets to a new, secure wallet. Always verify links and domains—especially those mimicking brands—using PhishDestroy’s real-time verification tools before taking any action.
Gönderilen kanıt anlık görüntüsü
- Gönderildi
- Kayıt defteri kayıtları
- 1
- Vaka kimliği
PD-20260408-15BEAF- Yakalanan sayfa başlığı
- Alveon
- PDF belgesi
- PDF kanıtı
Hukuki dayanak
Kanıtın tam metni
Illegal Activities: Active phishing operation targeting victims
Fraud & Deception: Impersonation of legitimate services
Identity Theft: Collection of credentials under false pretenses
Applicable Laws (KN):
International Anti-Cybercrime Regulations
Budapest Convention on Cybercrime
Universal Fraud Prevention Laws
Phishing activities violate international cybercrime conventions and KN's domestic fraud laws.
Action Required: This evidence-backed report demonstrates clear violations requiring suspension per your policies. Continued hosting exposes your organization to regulatory scrutiny and potential legal liability.
Data Coverage
Tehdit Müdahale Pipeline
Engelleme listesi kapsamı
10 izlenen harici kaynak · kayıtlı anlık görüntü 10.08.2026
Kaydedilen görüntü
Etki Alanı Analizi
Teknik ayrıntılarDNS, TLS adları ve zaman damgaları
ICANN OVERSIGHT
Registration: alveonltd.com
Akreditasyon ve RAA bağlamı
Akreditasyon ve RAA bağlamı
Registrar accreditation and DNS abuse obligations
For the registrable domain alveonltd.com behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
VirusTotal Analizi
Bu Siteden Etkilendiniz mi?
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.
Herhangi Bir Alan Adını Kontrol Et
Saklanan engelleme listesi, WHOIS, DNS ve genel tarama kanıtlarını kullanarak tehdit analizi
Şimdi TaraOltalama Olayını Bildir
Şüpheli alan adlarını tehdit veritabanımıza bildirin — topluluğu koruyun
BildirCanlı Tehdit Akışı
Son kimlik avı raporları ve gözlemlenen kullanılabilirlik değişiklikleri
İzleGelişmelerden Haberdar Olun, Güvende Kalın
Canlı tehditleri izleyin veya bunun yanlış bir uyarı olduğunu düşünüyorsanız bu kayda itiraz edin