1musk[.]co
“Trump x Musk — Official BTC, ETH & DOGE Giveaway!”
1musk.co — Неперевірений. Тип шахрайства: Fake Airdrop. Зведення доказів: VirusTotal 5/91 (alphaMountain.ai, Forcepoint ThreatSeeker, Fortinet, Gridinsoft, SOCRadar); PhishDestroy score 71/100. Реєстратор: Dynadot.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
1musk.co is an active malicious site observed on July 12, 2026 that leverages a fabricated giveaway narrative involving former President Trump and entrepreneur Elon Musk. The landing page advertises a “Trump x Musk — Official BTC, ETH & DOGE Giveaway!” and attempts to lure victims into submitting cryptocurrency wallet credentials. The site returns HTTP 200 and presents a valid Let’s Encrypt certificate (E8), indicating the operators have obtained a standard TLS certificate to increase perceived legitimacy. The domain was registered on February 21, 2026 through Dynadot LLC and resolves to the IPv4 address 5.189.161.88, which is hosted in France under ASN 51167 belonging to Contabo GmbH. Authoritative name servers are ns1.dyna-ns.net and ns2.dyna-ns.net, both typical of Dynadot‑managed domains. The hosting provider and the use of a free certificate are common tactics for rapidly deployed phishing infrastructure. Reputation services flag the site as high‑risk. Gridinsoft assigns a trust score of 0 out of 100, and VirusTotal reports that 2 of 95 scanned security vendors flag the domain as malicious. The domain appears on one external blocklist and is already listed by the PhishDestroy sink‑hole, confirming active mitigation by at least one security community. The combination of a fresh registration, low trust score, and limited but positive detection across vendors supports the high‑risk classification. Defenders should block 1musk.co at perimeter and DNS layers, and add the IP address 5.189.161.88 to any network‑level deny lists. Continuous monitoring of the associated name servers and the ASN can reveal additional infrastructure reused in future campaigns. End‑user awareness messaging should highlight the fake giveaway lure and advise against providing cryptocurrency wallet information to unsolicited sites. Incident response teams should treat any compromise related to this domain as a credential‑theft event and initiate standard containment and forensic procedures.
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Аналіз VirusTotal
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога