VirusTotal
2 / 91
“Mintory | NFT Marketplace”
bigmintnft.online — Контент недоступний. Уособлення бренду: Genericcrypto; Тип шахрайства: Nft Scam. Зведення доказів: VirusTotal 2/91 (ADMINUSLabs, Kaspersky); URLQuery 1 alert; URLScan malicious verdict; 2 external blocklist matches (MetaMask, SEAL); cloaking observed; PhishDestroy score 90/100. Реєстратор: Porkbun.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
2 / 91
1 threat-system alert
Повідомитиmalicious
Повідомитиchecked — no match recorded
no community references
Повідомитиprovider verdict: clean
Повідомитизбережений звіт
Повідомити 12 перевірено — блокувань немає
64/100
ПовідомитиChecked; no threat flag recorded
Повідомити| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DNS4EU | bigmintnft.online |
malicious | Sinkholed |
PhishDestroy has launched an active investigation into the domain bigmintnft.online, flagged for brand impersonation targeting the NFT Mint Scam vertical. The domain utilizes a near-identical visual and lexical mimicry of legitimate NFT mint platforms to deceive users into connecting crypto wallets and initiating unauthorized transfers. Technical artifacts suggest the presence of a crypto drainer kit, intended to siphon tokens upon wallet connection. Registrant behavior and landing-page structure replicate established NFT scam playbooks, including fraudulent mint calendars and counterfeit whitelisting prompts. Current evidence points to a high-fidelity clone aimed at capitalizing on user trust in NFT launch ecosystems.
Technical indicators confirm the following attributes: VirusTotal detection score at 2/95 engines as of UTC timestamp, domain creation on October 26, 2025, resolution to IP 198.251.89.229, registration via Porkbun LLC, and an SSL certificate issued by Let’s Encrypt. Google Safe Browsing (GSB) status remains unflagged, and open-source blocklists (AbuseIPDB, PhishTank, OpenPhish) show zero current listings for the domain or IP. The domain’s age and clean detection history suggest either a newly deployed operation or one carefully evading signature-based defenses.
This domain remains ACTIVE with an UNDER INVESTIGATION risk status and moderate operational maturity. PhishDestroy has escalated telemetry to industry partners and is coordinating takedown support requests to registrar Porkbun LLC and hosting provider. Users are advised to immediately block the domain and IP at network and endpoint levels. For mitigation, enable wallet-draining protections (e.g., native transaction simulation or hardware wallet confirmation prompts), verify official mint domains via project Discord/official site, and report any suspicious wallet interactions to phishing intelligence feeds.
Ця сторінка повертала один відповідь відвідувачу, що використовував браузер, та інший — пошуковому роботу або сканеру безпеки. Маскування застосовується виключно для того, щоб унеможливити доступ рецензентів до справжньої цільової сторінки.
status_splitПримітка щодо сканера: unavailable: raw=connection_error; http=0; via=http_proxy; error=SOCKSHTTPConnectionPool(host='bigmintnft.online', port=80): Max retries exceeded with url: / (Caused by NewConnectionErr
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
ns112.my-control-panel.comLocation describes the IP network.
Saved certificate metadata. Certificate dates without a timezone are shown as stored. Transport encryption does not establish that the site is trustworthy.
Google PageSpeed Insights — mobile performance audit of bigmintnft.online · checked Apr 27, 2026
11 recorded events. These records describe collected evidence, outgoing notifications and publication; they do not confirm a complete investigation or a takedown.
We scan suspicious URLs, inspect public results and send evidence through the appropriate abuse-reporting channels. The dated events above show what is recorded for this domain. The directory below explains the wider workflow.
Capture the rendered page, requests and visible infrastructure.
Compare the available engine results and retain the analysis timestamp.
Check whether Google currently lists the URL as unsafe.
Inspect a public scan and its recorded network and classification data.
Look for indicator references and related community intelligence.
Compare archived captures and preserve historical context.
Look for matching indicators and associated threat records.
Inspect certificate records and related hostnames.
Compare security resolver responses and record observed blocking.
Inspect the public DNS, TLS, HTTP and technology surface.
Security services used for scanning, reputation checks and reporting are listed below. A service being listed is not evidence that it received, accepted or acted on this particular domain. Recorded submissions appear in the notification history above.
Повідомив 1 учасник спільноти; уперше помічено 27.04.2026
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Template-based draft · optional AI wording assistance requires separate consent
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразДодавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиОстанні звіти про фішинг і помічені зміни доступності
ВідстежуватиСлідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога