dolphin-exchange[.]com
“Buy”
The domain dolphin-exchange.com was registered on 21 February 2026 through Web Commerce Communications Limited. It hosts a website whose title is “Buy” and returns HTTP 200 responses. The site is currently active and has been classified as a fake cryptocurrency exchange used in a phishing campaign. The domain’s trust score from Gridinsoft is 0 out of 100, and it is listed on at least one public blocklist, with PhishDestroy already blocking it.
Infrastructure analysis shows the domain resolves to 172.67.177.186, an IP address owned by Cloudflare, Inc. (AS13335) and located in the United States. DNS resolution is served by the authoritative nameservers cody.ns.cloudflare.com and gigi.ns.cloudflare.com. The TLS certificate is issued by Google Trust Services under the WE1 intermediate, indicating a standard HTTPS configuration without certificate anomalies.
Technical profiling reveals a modern JavaScript stack: Node.js, Vue.js, Nuxt.js, Chart.js, with assets delivered via jsDelivr, cdnjs, Google Analytics, and Facebook Pixel. The presence of financial charting libraries aligns with the reported “Fake Exchange” scam type, suggesting the site mimics legitimate trading platforms to harvest credentials. VirusTotal analysis flags the domain on 2 of 95 scanners, reinforcing the suspicion of malicious intent. No additional intelligence on payload delivery or credential harvesting endpoints is presently available.
Defenders should block traffic to dolphin-exchange.com at the network perimeter and add the domain to DNS sinkhole lists. Monitoring should extend to outbound connections to the identified Cloudflare IP and to the associated nameservers. Since the site leverages common CDN and analytics services, detection may require heuristic inspection of request patterns, especially POST submissions to pages resembling login or transaction forms. Continued observation of VirusTotal and other threat feeds is advised to capture any escalation or new indicators of compromise.
Процес реагування на загрози Pipeline
Перевірка за блок-листами
Джерел: 10 · синхронізовано 09.08.2026
Хронологія виявлення
Збережені спостереження у хронологічному порядку.
-
Cloudflare Radar
Cloudflare Radar: уперше зафіксовано як https://radar.cloudflare.com/scan/fc4baf9b-b771-4bc7-9fff-8a47d3554564
Збережений знімок
Аналітика доменів
Технічні подробиціDNS, SAN-адреси SSL, мітки часу
ICANN OVERSIGHT
Акредитація та контекст RAA
Акредитація та контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Аналіз VirusTotal
Аналіз продуктивності сайту
Google PageSpeed Insights — mobile performance audit of dolphin-exchange.com · checked Mar 2, 2026
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога