cardpix[.]icu
“CardPIX — Troca de criptomoedas”
cardpix.icu — Помилка сервера (HTTP 502). Зведення доказів: VirusTotal 6/93 (CyRadar, Forcepoint ThreatSeeker, Fortinet, Gridinsoft, Kaspersky); URLQuery 1 det.; Spamhaus DBL_PHISH; PhishDestroy score 70/100. Реєстратор: NiceNIC.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
The domain cardpix.icu presents as a cryptocurrency exchange platform under the name "CardPIX — Troca de criptomoedas," indicating a Portuguese-language targeting for trading services. The site poses a threat as a potential phishing or fraudulent exchange site, likely designed to deceive users into providing credentials or transferring cryptocurrency assets to threat actors.
Technical analysis reveals 6 out of 95 antivirus engines on VirusTotal flagged the domain as malicious, with detections from CyRadar, Forcepoint ThreatSeeker, Fortinet, Gridinsoft, and Kaspersky. The domain was registered on 2026-02-21 through NiceNIC International Group Co., Limited, a registrar associated with high-risk domains. It is hosted on IP 172.67.168.80 (United States) under AS13335 Cloudflare, Inc., with nameservers gina.ns.cloudflare.com and jaime.ns.cloudflare.com. The site lacks an SSL certificate, indicating no encrypted connection. It appears on one blocklist.
Currently, the domain is offline/down, but its registration date and registrar profile suggest it is part of a short-lived scam operation. The risk level is high due to confirmed malicious flags, lack of SSL, and recent creation, indicating active threat potential if the site becomes accessible again.
Розвіддані з мережевої безпеки Registrar context
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Збережений знімок
Аналітика доменів
Технічні деталіDNS, SAN-адреси SSL, мітки часу
ЗОНА SHORTDOT · ПУБЛІЧНІ ДОКАЗИ
.icu
ShortDot zone evidence
ShortDot zone evidence
The linked repository preserves daily zone observations across seven ShortDot-operated TLDs, including registration volume and abuse-related indicators. This registry context is supporting background and is not an independent detection for the domain in this report.
ICANN OVERSIGHT
Акредитація та контекст RAA
Акредитація та контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Latest Classified Outcome 2026-08-13 02:54:55 UTC
Аналіз VirusTotal
Архівні докази
Докази та зовнішні звіти
PD-20260215-B00AF5 Recipient: abuse@nicenic.net, abuse@gen.xyz, compliance@icann.org Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога