custodial-dextradingclaims[.]pages[.]dev
“Multi Chain Protocol”
custodial-dextradingclaims.pages.dev — Неперевірений. Тип шахрайства: Generic Phishing. Зведення доказів: VirusTotal 12/91 (alphaMountain.ai, BitDefender, CyRadar, ESET, Forcepoint ThreatSeeker); 1 external blocklist match (ScamSniffer); PhishDestroy score 86/100. Реєстратор: Cloudflare.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
Analysis indicates that custodial-dextradingclaims.pages.dev is an active crypto drainer infrastructure hosting a site titled "Multi Chain Protocol". The domain was created on 2024-06-11 and is registered through Cloudflare, Inc., using Cloudflare nameservers nora.ns.cloudflare.com and owen.ns.cloudflare.com. DNS resolution points to IP 188.114.96.3, an address owned by AS13335 Cloudflare in the United States. The web server presents a Google Trust Services / WE1 SSL certificate, enforces HSTS, and supports HTTP/3, returning HTTP 200 for the landing page. Security telemetry shows a Gridinsoft trust score of 0/100 and inclusion on a single blocklist (PhishDestroy). VirusTotal scans report that 9 of 91 security vendors flag the domain, reinforcing a high‑risk classification. While the site’s content has not been manually inspected, the combination of a recent registration, low trust score, blocklist presence, and multiple vendor detections aligns with known crypto‑drainer tactics that lure victims into transferring digital assets. Defenders should block the domain and its resolving IP at perimeter defenses, monitor for outbound connections to the address, and update intrusion‑detection signatures to flag any HTTP requests containing the "Multi Chain Protocol" title. Continuous threat‑intel feeds should be consulted for potential expansions of this infrastructure, and incident response teams should be prepared to investigate any compromised cryptocurrency wallets linked to traffic originating from this domain.
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Технології · 3 identified
HTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org 100% впевненостіCloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com 100% впевненостіHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100% впевненостіАналіз VirusTotal
Архівні докази
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога