Перейти до звіту про безпеку
⚠️
Цей домен було позначено як шкідливий
Системи безпеки повідомляють про виявлення: 18. Будьте дуже обережні — не вводьте облікові дані чи особисту інформацію.
ABUSE NOTICE · 7D+ OPEN Outgoing abuse reports are recorded; the latest stored availability evidence still shows the domain reachable.
Notification and current-status evidence

The sent-report ledger records the first outgoing report at . The recorded recipient is abuse@globaldomaingroup.com. The latest stored availability evidence still shows the domain reachable; 6 months has elapsed since the first outgoing report.

ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.

Elapsed since first report
6 months
Reports sent
1
Latest case ID
PD-20260213-26CDCC
Current status
Observed active at latest stored check
Безпека домену та аналіз загроз

change-noww[.]click

“Instant Cryptocurrency Exchange | Best Rates &Lowest Fees | ChangeNOW”

Загрозливий вердикт Критичний 100/100 оцінка доказів
Доступність Неперевірений Поточна доступність не перевірена
Виявлення VirusTotal: 18/93 Spamhaus DBL: DBL_PHISH URLQuery threat systems: 3 alerts Тип шахрайства: Fake Exchange
13.02.2026 1 Report Sent
Огляд звіту

change-noww.click — Неперевірений. Тип шахрайства: Fake Exchange. Зведення доказів: VirusTotal 18/93 (ADMINUSLabs, alphaMountain.ai, BitDefender, CRDF, CyRadar); URLQuery 3 alerts; Spamhaus DBL_PHISH; CF Radar malicious; PhishDestroy score 100/100. Реєстратор: Global Domain Group.

Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.

Зведення доказів
КРИТИЧНИЙ
Посилання
174BED5B
Оцінка
100/100

This domain, change-noww.click, poses a direct financial threat by impersonating a legitimate cryptocurrency exchange platform. Analysis indicates the site was designed to deceive users into entering sensitive credentials, such as wallet private keys or login details, under the pretense of offering instant cryptocurrency exchanges with low fees. The fraudulent nature of this operation is evident from its attempt to mimic trusted services, potentially leading to unauthorized access to digital assets and financial loss for unsuspecting victims. Infrastructure analysis reveals multiple red flags confirming the malicious intent of change-noww.click. The domain was registered on February 21, 2026, through Global Domain Group LLC, a registrar frequently associated with high-risk domains. It resolves to the IP address 62.60.226.213, hosted under AS214351 (FEMO IT SOLUTIONS LIMITED) in Germany, an autonomous system with a history of hosting phishing infrastructure. At the time of assessment, 18 out of 95 security vendors on VirusTotal flagged the domain as malicious, with one security blocklist (PhishDestroy) explicitly listing it. Additionally, the absence of an SSL certificate further undermines any claim to legitimacy, as secure financial platforms universally employ encryption. Users who may have interacted with change-noww.click should take immediate corrective action to mitigate potential risks. If credentials or private keys were entered on the site, affected individuals should transfer any remaining cryptocurrency holdings to a new, secure wallet and revoke access to any connected applications or services. It is also recommended to monitor financial accounts and digital wallets for unauthorized transactions. For enhanced security, users should enable multi-factor authentication on all cryptocurrency exchange accounts and consider using hardware-based security keys. Given the elevated risk level associated with this domain, vigilance is advised when engaging with any unsolicited financial offers or exchange services.

VirusTotal
VirusTotal
18 det.
URLQuery
URLQuery
3 threat alerts
CF Radar
Шкідливий
URLScan
URLScan
ScamAdviser
Scamadviser
7/100
Зафіксований статус
Неперевірений
PhishDestroy
DestroyList
У списку
Reports Sent
1
Обсяг даних VirusTotal 18 / 93 URLQuery 3 threat-system alerts PhishStats checked — no match recorded OTX no community references CF Radar provider verdict: malicious URLScan capture збережений звіт URLScan verdict висновок недоступний Блокування DNS не перевірено TLS немає даних сертифіката WHOIS not parsed Знімок екрана 3 captures · 3 sources Ланцюжок перенаправлень не досліджено Scamadviser 7/100
Сигнали безпеки
SA Scamadviser Warnings 7/100
The Tranco rank (how much traffic) is rather low The server of the site has several low reviewed other websites Cryptocurrency services detected, these can be high risk The age of this site is (very) young.
We found that the website is using an external review system This website offers payment methods which offer a "money back services" We found a valid SSL certificate DNSFilter labels this site as safe
Розвіддані з мережевої безпеки
Threat Detection Systems 3 alerts
Detection System Indicator Verdict Alert
Hagezi Threat Feed change-noww.click malicious Sinkholed
DNS4EU change-noww.click malicious Sinkholed
OpenDNS change-noww.click phishing Phishing Block
CF Cloudflare Radar Verdict Шкідливий
Security Risks Phishing

Процес реагування на загрози Pipeline

Відкриття
Checks
Reports
Доступність
16/17
Sent Report Recorded
Stored sent-report record for registrar Global Domain Group LLC, hosting provider, 2 abuse contacts
abuse@globaldomaingroup.comabuse@as214351.com
13.02.2026

Статус у публічних блоклистах

Збережений знімок

Заголовок сторінки
Instant Cryptocurrency Exchange | Best Rates &Lowest Fees | ChangeNOW

Аналітика доменів

Домен
Telegram IoCs 2 extracted https://t.me/changeNOW_chat https://t.me/ChangeNOW_officialbot
Сервер / ASN Apache/2.4.52 (Ubuntu) · AS214351 FEMOIT FEMO IT SOLUTIONS LIMITED, GB
Репутація IP abuse score 0/100 0 reports checked 27.07.2026
Реєстратор Global Domain Group US(US)
IP-адреса 62.60.226.213 DE
ГеолокаціяDE Frankfurt am Main, DE
МережаAS214351 · FEMO IT SOLUTIONS LIMITED
Зворотний пошук IPviewdns.info → rapiddns.io →
РеєстраціяExpires 08.02.2027
Elapsed Since First Report 15 days
Що ми враховуємо Raw elapsed time since the first stored abuse report. It is not a registrar response-time measurement. Latest observed status: Неперевірений.
Що містить кожен звіт Збережені записи вихідних звітів можуть посилатися на докази, доступні на той час, наприклад вердикти постачальників, реєстраційні дані, деталі хостингу, класифікації або знімки екрана. Ця сторінка не визначає точного доставленого корисного навантаження, квитанції, підтвердження чи дії одержувача.
Технічні деталіDNS, SAN-адреси SSL, мітки часу
Вперше виявлено13.02.2026
DOM Analysisanalyzed 27.07.2026score 88/100
IoC Extractionscanned 29.07.20260 wallet · 2 Telegram IoCs
Submitted URLhttps://change-noww.click/
Сервери іменns-cloud-e4.googledomains.com
TLS Observationscanned 10.08.2026
Case ID
ICANN OVERSIGHT

Акредитація та контекст RAA

Registrar accreditation and DNS abuse obligations

For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.

Accreditation is a contract, not a safety certification.

RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.

Accountability draft Нічого не надсилається автоматично.
Технології · 7 identified
Ubuntu
Operating systems

Ubuntu is a free and open-source operating system on Linux for the enterprise server, desktop, cloud, and IoT.

www.ubuntu.com 100% впевненості
Bootstrap
UI frameworks

Bootstrap is a free and open-source CSS framework directed at responsive, mobile-first front-end web development. It contains CSS and JavaScript-based design templates for typography, forms, buttons, navigation, and other interface components.

getbootstrap.com 100% впевненості
React
JavaScript frameworks

React is an open-source JavaScript library for building user interfaces or UI components.

reactjs.org 100% впевненості
Apache HTTP Server
Web servers

Apache is a free and open-source cross-platform web server software.

httpd.apache.org 100% впевненості
Trustpilot
Reviews

Trustpilot is a Danish consumer review website which provide embed stand-alone applications in your website to show your most recent reviews, TrustScore, and star ratings.

business.trustpilot.com 100% впевненості
LiveChat
Live chat

LiveChat is an online customer service software with online chat, help desk software, and web analytics capabilities.

www.livechat.com 100% впевненості
Ahrefs
SEO Analytics

Ahrefs is an online toolset utilised for search engine optimisation (SEO) and competitor analysis, which permits users to analyse their website's performance, track keyword rankings, identify backlink opportunities, and research competitors' websites, among other features.

ahrefs.com 100% впевненості
Detected via Cloudflare Radar · Wappalyzer engine
Поскаржитися на цей домен Надішліть докази та допоможіть захистити інших

Аналіз VirusTotal

18 / 93 постачальників безпеки позначили цей домен
View on VT
Last analyzed
ADMINUSLabs
alphaMountain.ai
BitDefender
CRDF
CyRadar
ESET
Emsisoft
Fortinet
G-Data
Gridinsoft
«Касперський»
Lionic
Netcraft
Seclookup
SOCRadar
Sophos
VIPRE
Webroot

Архівні докази

Wayback Machine Snapshot
Для перегляду доказів доступний історичний знімок
View Archive

Докази та зовнішні звіти

Submitted Evidence Snapshot
Sent: Ledger records: 1 Case ID: PD-20260213-26CDCC Recipient: abuse@globaldomaingroup.com
Page title stored with report: Instant Cryptocurrency Exchange | Best Rates &Lowest Fees | ChangeNOW
URLScan evidence VirusTotal evidence URLQuery evidence Screenshot 87.2 KB

Чи вплинув на вас цей сайт?

If credentials were compromised, report immediately. Do not engage with recovery scammers.

Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.

Європол
Знайдіть офіційний канал звітності для вашої країни ЄС
National police directory
Остерігайтеся шахраїв, які обіцяють повернути втрачені кошти! Злочинці можуть знову зв’язатися з жертвами, видаючи себе за слідчих, адвокатів або агентів із відновлення. Не сплачуйте авансових зборів і не діліться обліковими даними. Дізнайтеся більше про шахрайство у сфері відшкодування збитків →

Зверніться до місцевих органів влади

Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.

Довідник 97 країн
Чернетка за допомогою штучного інтелекту — деталі інциденту обробляються постачальником штучного інтелекту Перегляньте та подайте його самостійно

Перевірити будь-який домен

Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування

Сканувати зараз

Повідомити про фішинг

Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту

Повідомити

Потокова стрічка про загрози

Останні звіти про фішинг і помічені зміни доступності

Відстежувати

Будьте в курсі подій, дбайте про свою безпеку

Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога

Потокова стрічка про загрози Оскаржити це оголошення
HTML · IFRAME

Вбудувати цей звіт

Поділіться цією інформацією про загрози на своєму веб-сайті або в блозі

embed.html
<iframe
  src="https://phishdestroy.io/uk/embed/domain/change-noww.click"
  title="PhishDestroy threat report for change-noww.click"
  width="100%" height="320"
  loading="lazy"
  referrerpolicy="no-referrer"
  sandbox="allow-same-origin allow-popups allow-popups-to-escape-sandbox"
  style="border:0;border-radius:12px;max-width:100%"
></iframe>

Дуже щирий лист-подяка

Генератор сатиричних чернеток

Одержувач
Контекст зборів

Це сатирична чернетка. Суми зборів є оцінками; ми не стверджуємо, що вони точно стосуються цього домену.