pub-f1e213d7f7cb4ce7ba1028767eebb8db[.]r2[.]dev
“Not Found”
pub-f1e213d7f7cb4ce7ba1028767eebb8db.r2.dev — İçerik kullanılamıyor. Dolandırıcılık türü: Crypto Drainer. Kanıt özeti: VirusTotal 9/91 (ADMINUSLabs, alphaMountain.ai, Cluster25, CyRadar, ESET); URLQuery 3 alerts; PhishDestroy score 80/100. Kayıt kuruluşu: Cloudflare R2.
Özgün adli kaydı korumak için aşağıdaki ayrıntılı PhishDestroy AI analizi İngilizce bırakılmıştır.
PhishDestroy identifies pub-f1e213d7f7cb4ce7ba1028767eebb8db.r2.dev as an active crypto drainer distribution point designed to siphon cryptocurrency from unsuspecting users. This domain functions as a malicious payload host, serving crypto drainer scripts that silently connect to victims' wallets upon interaction, enabling unauthorized transfers. Security telemetry shows this infrastructure is weaponized for real-time theft under the guise of legitimate services, with the domain explicitly crafted to mimic common frontend hosts used by cloud storage providers. The threat actor leverages stolen session cookies and wallet approvals to bypass authentication and initiate rogue transactions without additional prompts.
This domain is not just another phishing page—it is a verified malicious node in a wider cryptocurrency theft campaign. VirusTotal analysis confirms that 9 out of 95 security vendors have flagged this domain as malicious, while it additionally appears on three independent blocklists including OpenPhish, PhishingArmy, and OISD. The domain resolves to IP address 104.18.54.45 and utilizes a legitimate Let's Encrypt SSL certificate to maintain the appearance of authenticity. Despite its professional appearance, technical analysis reveals it was registered recently and is being actively used to distribute crypto drainer malware.
If you have interacted with this domain—especially by clicking links, downloading files, or connecting your wallet—take immediate action. Disconnect any affected wallets from the internet, revoke any suspicious approvals, and review transaction logs for unauthorized activity. Use tools like PhishDestroy to validate the domain's status and scan your system for wallet compromise. Clear browser caches, remove any related browser extensions, and consider rotating wallet addresses and private keys if exposure is suspected. Stay vigilant: crypto drainers often hide in plain sight, masquerading as tools or services within legitimate ecosystems.
Ağ Güvenliği İstihbaratı
Tehdit Müdahale Pipeline
Genel Engelleme Listesi Durumu
Teknolojiler · 2 identified
HTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org %100 güvenCloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com %100 güvenVirusTotal Analizi
Site Performans Analizi
Google PageSpeed Insights — mobile performance audit of pub-f1e213d7f7cb4ce7ba1028767eebb8db.r2.dev · checked Apr 28, 2026
Kanıtlar ve Dış Raporlar
Bu Siteden Etkilendiniz mi?
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.
Herhangi Bir Alan Adını Kontrol Et
Saklanan engelleme listesi, WHOIS, DNS ve genel tarama kanıtlarını kullanarak tehdit analizi
Şimdi TaraOltalama Olayını Bildir
Şüpheli alan adlarını tehdit veritabanımıza bildirin — topluluğu koruyun
BildirCanlı Tehdit Akışı
Son kimlik avı raporları ve gözlemlenen kullanılabilirlik değişiklikleri
İzleGelişmelerden Haberdar Olun, Güvende Kalın
Canlı tehditleri izleyin veya bunun yanlış bir uyarı olduğunu düşünüyorsanız bu kayda itiraz edin