Notification and current-status evidence
The sent-report ledger records the first outgoing report at .
The recorded recipient is abuse@dynadot.com.
The latest stored availability evidence still shows the domain reachable; 2 months has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
confirmtx[.]net
confirmtx.net için kimlik avı ve güvenlik kontrolü
“Bitcoin Transaction Accelerator - ConfirmTX”
confirmtx.net — Doğrulanmamış. Marka kimliğine bürünme: Bitcoin; Dolandırıcılık türü: Brand Impersonation. Kanıt özeti: VirusTotal 9/91 (BitDefender, CyRadar, Fortinet, G-Data, Gridinsoft); URLQuery 1 alert; 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 85/100. Kayıt kuruluşu: Dynadot.
Özgün adli kaydı korumak için aşağıdaki ayrıntılı PhishDestroy AI analizi İngilizce bırakılmıştır.
This domain, confirmtx.net, operates as a high-risk phishing infrastructure designed to impersonate Bitcoin-related services. Analysis indicates the site presents itself as a "Bitcoin Transaction Accelerator" under the page title "Bitcoin Transaction Accelerator - ConfirmTX," targeting users seeking to expedite cryptocurrency transactions. The domain employs social engineering tactics to harvest credentials, private keys, or other sensitive information from victims under the guise of a legitimate service. The threat specifically exploits trust in Bitcoin branding to deceive users into interacting with malicious infrastructure. Infrastructure analysis reveals multiple technical indicators supporting this assessment. The domain resolves to IP address 104.21.82.240 and is registered through Dynadot Inc. Security vendors on VirusTotal flagged confirmtx.net at a ratio of 10/95, while it appears on three distinct security blocklists. AlienVault OTX records the domain in two threat intelligence pulses, further corroborating its malicious nature. The site employs technologies including particles.js, Semantic UI, jQuery, and Cloudflare, with an SSL certificate issued by Google Trust Services. Despite its current offline status, historical data confirms its use in active phishing campaigns. Users who visited confirmtx.net or interacted with its content should immediately revoke any permissions granted to the site, particularly within cryptocurrency wallets or browser extensions. All credentials, private keys, or recovery phrases entered on the site must be considered compromised and replaced. Monitor associated accounts for unauthorized transactions or access attempts. If financial loss occurred, report the incident to relevant authorities and cryptocurrency exchange platforms for potential recovery or mitigation efforts. Exercise heightened caution with future Bitcoin-related services, verifying domain legitimacy through official sources before interaction.
Ağ Güvenliği İstihbaratı
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DNS4EU | confirmtx.net |
malicious | Sinkholed |
Tehdit Müdahale Pipeline
Genel Engelleme Listesi Durumu
Kaydedilen görüntü
Etki Alanı Analizi
Teknik ayrıntılarDNS, SSL SAN’ları, zaman damgaları
ICANN OVERSIGHT
Akreditasyon ve RAA bağlamı
Akreditasyon ve RAA bağlamı
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Teknolojiler · 5 identified
Semantic UI is a front-end development framework, powered by LESS and jQuery.
semantic-ui.com %100 güvenjQuery is a JavaScript library which is a free, open-source software designed to simplify HTML DOM tree traversal and manipulation, as well as event handling, CSS animation, and Ajax.
jquery.com %100 güvenCloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com %100 güvenHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org %100 güvenVirusTotal Analizi
Kanıtlar ve Dış Raporlar
PD-20260607-EBDC47 Recipient: abuse@dynadot.com Bu Siteden Etkilendiniz mi?
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.
Herhangi Bir Alan Adını Kontrol Et
Saklanan engelleme listesi, WHOIS, DNS ve genel tarama kanıtlarını kullanarak tehdit analizi
Şimdi TaraOltalama Olayını Bildir
Şüpheli alan adlarını tehdit veritabanımıza bildirin — topluluğu koruyun
BildirCanlı Tehdit Akışı
Son kimlik avı raporları ve gözlemlenen kullanılabilirlik değişiklikleri
İzleGelişmelerden Haberdar Olun, Güvende Kalın
Canlı tehditleri izleyin veya bunun yanlış bir uyarı olduğunu düşünüyorsanız bu kayda itiraz edin