Здійснюйте пошук серед відстежуваних доменів та переглядайте збережені докази, виявлені випадки та останні дані щодо доступності.
195,295
Загальна кількість відстежених
195,295
Виявлено VT
87,901
Останнє підключення: активний
98,138
Недоступний під час останньої перевірки
0
VT — у процесі розгляду
How This Attack Works
Fake Token Presale scams trick victims into believing they are investing in legitimate cryptocurrency projects. Here's how the scam typically unfolds:
STEP 1
Create Fake Websites
Scammers set up realistic-looking websites mimicking legitimate token presale portals.
STEP 2
Promote Presale on Social Media
Using social media and fake endorsements, scammers attract potential investors.
STEP 3
Collect Cryptocurrency
Victims are prompted to send cryptocurrency to a specified address under the guise of buying tokens.
STEP 4
Disappear with Funds
Once funds are collected, scammers shut down the site and disappear, leaving victims without recourse.
Technical Analysis
Fake Token Presale scams often leverage phishing tactics combined with cryptocurrency-specific techniques. Attackers use homograph attacks to create URLs that closely resemble legitimate sites, often registered through top registrars like NICENIC INTERNATIONAL GROUP CO., LIMITED and PDR Ltd. d/b/a PublicDomainRegistry.com. They exploit the decentralized nature of blockchain networks, utilizing smart contracts that mimic legitimate presale contracts but are programmed to divert funds to the attacker’s wallet. The infrastructure often involves cloud-based hosting services to quickly deploy and dismantle sites, minimizing the chance of detection. HTML and JavaScript are commonly used to create dynamic, convincing interfaces that reassure potential victims of the site’s legitimacy. Additionally, attackers might deploy SEO techniques to improve the visibility of their fraudulent sites in search engine results, further increasing their reach.
Real Cases
CryptoX Presale Scam (2024)
$2 million stolen
A fake presale for a non-existent token, CryptoX, duped investors into contributing significant sums.
TokenLaunch Fraud (2023)
$1.5 million stolen
Victims were lured into a fake token launch with promises of high returns, only for the site to vanish post-collection.
QuickCoin Deception (2024)
$3 million stolen
Scammers created a sophisticated site mimicking a known exchange, leading to substantial financial losses.
How to Detect
Перевірити for slight misspellings in domain names.
Look for inconsistent branding or layout compared to legitimate sites.
Be wary of unsolicited investment opportunities via social media.
Verify presale details on official project channels.
Beware of high-pressure tactics urging immediate investment.
How to Protect Yourself
1
Always verify URLs before entering personal information.
2
Use browser extensions to detect phishing attempts.
3
Consult official project websites or channels for presale information.
4
Enable two-factor authentication on cryptocurrency exchanges.
5
Звіт suspicious sites to authorities and platforms like PhishDestroy.
Frequently Asked Questions
Data sourced from PhishDestroy threat intelligence database — 237 domains tracked for this threat type
Fake Token Presale 237 domains

binance-dep30h.com

dreamsmart.pl

liquidchains.info

trdnetwork.info

baforth.guru

claims-bitcoinhyper.com

coiniist-rainbow.xyz

llittlepepe.com

mbato.guru

monoprotocol.info

mostgretoko.guru

ripplecareer.com

sonami-so.info

agaricproku.com

claims-snortertoken.com

hotoj.guru

prizelink.net

blazpay.org

coinlist-rainbow.xyz

colnilst.co

debraleslie.com

dep29k-binance.com

gro39k.info

invest-xai.com

moonbull.io

othersko.guru

pepeheimer.io

retikclaim.web.app

unisara.guru

xa500k.com

xa60zlaunch.com

zama.sale

003-bca.net

appie.shop

cradwin.com

dep26k-binance.com

gr0k2025.com

grok49k-cointelegraph.com

myxaicoin.pages.dev

pepeheimer-claim.com

purchase2-blockdags-networks.pages.dev

thecrito.guru

wallstreetpepe-online-d3n.pages.dev

best-wallettoken.com

blazpay.co

claim-pepenode.io

conilst.co

gro39k.org

grok25h.com

inqubetai-node.pages.dev

litltlepepe.com

myxaiconnects.net

octra.run

pump-presale.org

qaddun.com

ruviai.net

spx98k.com

timwarrencoin.io

unilabs.finance

bullzila.com

cryptoallstars-reward.web.app

grok54h-cointelegraph.com

one.link

pepeto-claiming.io

portalbridge.app

resolvetics.web.app

rnbw-coiniist.co

alphapepetokenpresale.online

claim.snortertokn.live

dashboard-bestwallet.firebaseapp.com

neexoraa.com

nx0b6we.pages.dev

reward-snortertoken.com

sale-maxidoge.com

basetoken.sale

bitcoinhyper.us

litlelpepe.com

pepeascensionclaim.pages.dev

qubeticsverification.web.app

xaifusion.com

grok35k-fxempire.com

magacoin.info

rainbows.run

spx15k.com

tapzi-io.xyz

www-grok-allocation.xyz

www.bestwalletsclaim.live

blockdagpresalenetwork.online

btchyperapp.pages.dev

grok35k.net

grok49k.com

harambeaiclaim.web.app

ionichain.com

spx21k.com

bdagnetwork.info
Процес реагування на загрози Pipeline
Як перевіряється кожен домен у цьому хабі та як нейтралізуються підтверджені загрози. Повна візуалізація технологічного процесу →
Перевірки даних про загрози— кожен домен проходить сканування та перехресну перевірку щодо:
urlscan.ioЗнімок екрана · DOM · HTTPVirusTotal90+ AV enginesGoogle Safe BrowsingTransparency ЗвітCloudflare RadarDNS · certs · categoriesAlienVault OTXThreat-intel pulsesWayback MachineHistorical evidenceabuse.ch ThreatFoxIOC correlationcrt.shCertificate TransparencyDNS Безпека FiltersQuad9 · AdGuard · CleanBrowsingWeb-ПеревіритиFull surface scan
Глобальна синхронізація постачальників— підтверджені випадки передаються 29 партнерам:
GoogleSafe BrowsingGoogleWeb Risk APIMicrosoftSmartScreenVirusTotalDetection feedCloudflareRadar / 1.1.1.1YandexSafe BrowsingURLScan.ioPublic scanESETWebGuardBitdefenderThreat exchangeNortonSafe WebSymantecОгляд сайтуAviraCloud detectionAvast / AVGWeb Shield«Касперський»OpenTIPDr.WebOnline scannerNetcraftЛіквідація APIPhishTankVerified voteAPWG eCXBulk feedPhishStatsOpen feedPhish.ЗвітHosting abuseSpamhausDBL feedPolySwarmMarketplaceCheckPhishBolster scanQutteraMalware scanURLquerySandboxCriminal IPAsset intelCRDFThreat CenterScamadviserTrust scoreMyWOTWeb of Trust