chang-nowe[.]at
“Changenow | Instant Crypto Exchange”
chang-nowe.at — Доступно · доступ обмежено (HTTP 403). Тип шахрайства: Fake Exchange. Зведення доказів: VirusTotal 15/91 (alphaMountain.ai, BitDefender, Chong Lua Dao, CRDF, CyRadar); PhishDestroy score 95/100. Реєстратор: Cloudflare.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
Analysis of the domain chang-nowe.at indicates it was operating as a phishing site targeting users of the Changenow cryptocurrency exchange platform. The domain was registered through Cloudflare, Inc. and utilized Cloudflare nameservers (dara.ns.cloudflare.com, ian.ns.cloudflare.com). Infrastructure analysis reveals the site resolved to the IP address 188.114.96.3, associated with AS1335 Cloudflare, Inc. in the United States. The SSL certificate was issued by Google Trust Services (WE1), a common configuration for Cloudflare-hosted domains.
At the time of assessment, the domain returned an HTTP 403 status, suggesting access restrictions or takedown measures. The page title, 'Changenow | Instant Crypto Exchange,' directly mimics the branding of the legitimate Changenow platform, reinforcing the likelihood of phishing intent. Despite the absence of detections from 95 vendors on VirusTotal at the time of scanning, this does not confirm the domain's safety; phishing sites frequently evade initial detection. The domain was flagged by at least one security blocklist (PhishDestroy) and has since been taken offline, though historical activity remains under investigation.
Defenders should treat this domain as confirmed malicious infrastructure. The use of Cloudflare hosting and nameservers is consistent with phishing campaigns seeking to obscure origin and leverage CDN protections. While the exact phishing kit or payload is not yet analyzed, the combination of brand impersonation, Cloudflare hosting, and blocklist inclusion warrants immediate blacklisting and monitoring for related domains. Further investigation into registration patterns and associated IPs may reveal additional compromised or malicious infrastructure.
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Технології · 2 identified
Cloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com 100% впевненостіHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100% впевненостіАналіз VirusTotal
Архівні докази
Докази та зовнішні звіти
“chang-nowe.at gf@nic.at tech-nic-at@nic.at service@nic.at registrar@nic.at recht@nic.at compliance@changenow.io reportphishing@apwg.org report@openphish.com https://abuse.cloudflare.com/phishing https://safebrowsing.google.com/safebrowsing/report_phish/ https://www.microsoft.com/en-us/wdsi/support/report-unsafe-site-guest https://msrc.microsoft.com/report/abuse?ThreatType=URL&IncidentType=Phishing https://www.microsoft.com/en-us/concern/bing https://www.scam-detector.com/submit-a-scam Malicious”
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога