Перейти до звіту про безпеку
⚠️
Цей домен було позначено як шкідливий
Системи безпеки повідомляють про виявлення: 12. Публічні списки блокувань, які повідомляють про збіг: 2. Будьте дуже обережні — не вводьте облікові дані чи особисту інформацію.
Безпека домену та аналіз загроз

fmescotce[.]top

“fmescotce - 全球领先的数字货币交易平台”

Загрозливий вердикт Критичний 92/100 оцінка доказів
Доступність Контент недоступний Вміст був недоступний під час останнього спостереження
Виявлення VirusTotal: 12/94 Збережений список блокувань відповідає: 2 URLQuery threat systems: 3 alerts Уособлення бренду: Google
22.04.2026 Google 1 Report Sent

Зведення доказів

КРИТИЧНИЙ
Evidence score
92/100

PhishDestroy identifies fmescotce.top as a high-risk fake cryptocurrency exchange phishing domain designed to deceive users into depositing digital assets. The site mimics a legitimate trading platform, complete with a Chinese-language interface and branding suggestive of a 'global leading digital currency exchange.' Security blocklists and browser safety services have flagged this domain due to its intent to harvest credentials and steal deposited funds. No known drainer kit signatures are publicly associated with this campaign yet, suggesting a potential new or evolving threat vector. The page title, 'fmescotce - 全球领先的数字货币交易平台,' reinforces the social engineering tactic, leveraging trust in established exchange branding to lure victims. This domain was flagged with a 12/95 VirusTotal detection score as of the latest scan, indicating that current antivirus and security solutions have not yet added signatures for this specific threat. The domain is registered through NameSilo, LLC, and resolves to IP address 45.197.12.38. Notably, the domain was created on March 28, 2026, which is an unusually recent registration date, a common tactic among phishing operators to avoid historical scrutiny. Google Safe Browsing classifies this domain under 'SOCIAL_ENGINEERING,' and it has been blocked by InversionDNS and appears on at least one additional security blocklist. The domain utilizes a Let's Encrypt SSL certificate, which is frequently exploited by phishing sites to appear legitimate. As of the latest assessment, fmescotce.top remains active and operational, with no signs of takedown or mitigation. The absence of detections on VirusTotal suggests that signature-based defenses are not yet effective against this threat, increasing the risk to potential victims. Immediate action is recommended to block access to this domain at the network level, and users are advised to avoid interacting with any site promoting 'fmescotce.top' or similar cryptocurrency exchange services. The remaining risk is high due to the domain's active status, lack of widespread detection, and the high potential for financial loss among unsuspecting users.

Знімок надісланих доказів

Надіслано
Записи журналу
1
ID справи
PD-20260422-66A8F6
Заголовок збереженої сторінки
fmescotce - 全球领先的数字货币交易平台
PDF-файл
PDF із доказами
Повний текст доказів
Policy Violations:
Illegal Activities: Active phishing operation targeting victims
Fraud & Deception: Impersonation of legitimate services
Identity Theft: Collection of credentials under false pretenses
Applicable Laws (Unknown):
International Anti-Cybercrime Regulations
Budapest Convention on Cybercrime
Universal Fraud Prevention Laws
Phishing activities violate international cybercrime conventions and Unknown's domestic fraud laws.
Action Required: This evidence-backed report demonstrates clear violations requiring suspension per your policies. Continued hosting exposes your organization to regulatory scrutiny and potential legal liability.
VirusTotal
VirusTotal
12 det.
URLQuery
URLQuery
3 threat alerts
Сертифікат TLS
Let's Encrypt
Вік
5 mo
Зафіксований статус
Контент недоступний HTTP 502
PhishDestroy
DestroyList
У списку
Reports Sent
1

Data Coverage

VirusTotal 12 / 94 URLQuery 3 threat-system alerts PhishStats checked — no match recorded OTX no community references CF Radar scan completed URLScan capture збережений звіт URLScan verdict Аналіз завершено Блокування DNS не перевірено TLS valid certificate, 79d WHOIS 5 mo old Знімок екрана 3 captures · 3 sources Ланцюжок перенаправлень не досліджено
Розвіддані з мережевої безпекиRegistrar context
Registrar context NameSilo
Stored registration data identifies NameSilo as the registrar. PhishDestroy maintains separate registrar investigations; that broader material is contextual and is not an independent detection for this domain.
Review source investigation
Threat Detection Systems 3 alerts
Detection System Indicator Verdict Alert
Hagezi Threat Feed fmescotce.top malicious Sinkholed
DNS4EU fmescotce.top malicious Sinkholed
Hagezi Threat Feed cdn.staticfile.org malicious Sinkholed

Процес реагування на загрози Pipeline

Відкриття
Checks
Reports
Доступність
14/14

Перевірка за блок-листами

10 зовнішніх джерел під наглядом · знімок від 12.08.2026

8 зовнішніх джерел під наглядом Збігів немає

Збережений знімок

Заголовок сторінки
fmescotce - 全球领先的数字货币交易平台
Сертифікат TLS
Valid transport encryption · Виданий Let's Encrypt · valid for 79 days

Аналітика доменів

Домен
URLScan Verdict Аналіз завершено score 0 report ↗
Google Safe Browsing Позначено Social engineering checked 22.04.2026
Сервер / ASN nginx · AS142002 Scloud Pte Ltd
Репутація IP IP abuse confidence 0/100 0 reports checked 13.07.2026
Реєстратор NameSilo US(US) PhishDestroy Investigation
Контакт для скаргabuse@namesilo.com
IP-адреса 45.197.12.38 MY
ГеолокаціяMY Kuala Lumpur, MY
МережаAS142002 · Cloud Innovation Ltd
Зворотний пошук IPviewdns.info → rapiddns.io →
РеєстраціяСтворено 28.03.2026 (137d)
Статус HTTP502 Error
Технічні подробиціDNS, імена TLS і часові мітки
Вперше виявлено22.04.2026
Submitted URLhttp://fmescotce.top/
Сервери іменpaityn.ns.cloudflare.comvern.ns.cloudflare.com
Відбиток TLS
Спостереження TLSдіє з 12.04.2026перевірено 22.04.2026
Альтернативні імена суб’єкта TLSwww.fmescotce.top
ICANN OVERSIGHT

Акредитація та контекст RAA

Registrar accreditation and DNS abuse obligations

For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.

Accreditation is a contract, not a safety certification.

RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.

Accountability draft Нічого не надсилається автоматично.

Технології

Виявлено 9 технологій із високою впевненістю

PHP ThinkPHP Bootstrap Vue.js Nginx Provide Support Marked jQuery HSTS
Cloudflare Radar
Поскаржитися на цей домен Надішліть докази та допоможіть захистити інших

Аналіз VirusTotal

12 / 94 постачальників безпеки позначили цей домен
View on VT
Last analyzed
ADMINUSLabs
alphaMountain.ai
CRDF
CyRadar
Forcepoint ThreatSeeker
Fortinet
G-Data
Google Safebrowsing
Gridinsoft
Netcraft
Seclookup
Sophos

Чи вплинув на вас цей сайт?

If credentials were compromised, report immediately. Do not engage with recovery scammers.

Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.

Європол
Знайдіть офіційний канал звітності для вашої країни ЄС
National police directory
Остерігайтеся шахраїв, які обіцяють повернути втрачені кошти! Злочинці можуть знову зв’язатися з жертвами, видаючи себе за слідчих, адвокатів або агентів із відновлення. Не сплачуйте авансових зборів і не діліться обліковими даними. Дізнайтеся більше про шахрайство у сфері відшкодування збитків →

Зверніться до місцевих органів влади

Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.

Довідник 97 країн
Чернетка за допомогою штучного інтелекту — деталі інциденту обробляються постачальником штучного інтелекту Перегляньте та подайте його самостійно

Перевірити будь-який домен

Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування

Сканувати зараз

Повідомити про фішинг

Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту

Повідомити

Потокова стрічка про загрози

Останні звіти про фішинг і помічені зміни доступності

Відстежувати

Будьте в курсі подій, дбайте про свою безпеку

Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога

Потокова стрічка про загрози Оскаржити це оголошення

Зовнішні інструменти

ScamAdviserScamAdviser Оцінка довіри 80/100Статус: Likely SafeВідкрити джерело
HTML · IFRAME

Вбудувати цей звіт

Поділіться цією інформацією про загрози на своєму веб-сайті або в блозі

embed.html
<iframe
  src="https://phishdestroy.io/uk/embed/domain/fmescotce.top"
  title="PhishDestroy threat report for fmescotce.top"
  width="100%" height="320"
  loading="lazy"
  referrerpolicy="no-referrer"
  sandbox="allow-same-origin allow-popups allow-popups-to-escape-sandbox"
  style="border:0;border-radius:12px;max-width:100%"
></iframe>

Дуже щирий лист-подяка

Генератор сатиричних чернеток

Одержувач
Контекст зборів

Це сатирична чернетка. Суми зборів є оцінками; ми не стверджуємо, що вони точно стосуються цього домену.