claims-etherexfi[.]app
“Dashboard - Etherex Exchange”
claims-etherexfi.app — Контент недоступний. Уособлення бренду: Genericcrypto; Тип шахрайства: Crypto Scam. Зведення доказів: VirusTotal 7/95 (ADMINUSLabs, alphaMountain.ai, CRDF, CyRadar, Forcepoint ThreatSeeker); URLScan malicious verdict; 3 external blocklist matches (Polkadot, Enkrypt, Codeesura); PhishDestroy score 74/100. Реєстратор: Cloudflare.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
The domain claims-etherexfi.app is identified as a crypto_drainer, impersonating the legitimate Etherex Exchange. The domain was registered through Cloudflare, Inc. and is associated with a malicious drainer kit designed to siphon cryptocurrency from unsuspecting users.
Infrastructure analysis reveals that claims-etherexfi.app resolves to the IP address 188.114.97.3. The domain has a VirusTotal score of 7/95, indicating that 7 security vendors out of 95 have flagged it as malicious. It is registered through Cloudflare, Inc., and was created on an unknown date. The domain appears on 4 security blocklists and has a Gridinsoft trust score of 0/100, reflecting a complete lack of trustworthiness.
Currently, the domain is offline, which may indicate that it has been taken down by security organizations or the registrar. Despite this, the domain remains a threat due to its presence on multiple blocklists and the potential for reactivation. Security teams are advised to monitor for any signs of the domain coming back online and to ensure that all network traffic is filtered to prevent any accidental access. The remaining risk is elevated, and users should be educated about the dangers of crypto_drainers and the importance of verifying the authenticity of websites before entering sensitive information.
Розвіддані з мережевої безпеки
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Збережений знімок
Аналітика доменів
Технічні деталіDNS, SAN-адреси SSL, мітки часу
ICANN OVERSIGHT
Акредитація та контекст RAA
Акредитація та контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Аналіз VirusTotal
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога