forexico[.]net
Перевірка домену forexico.net на фішинг і безпеку
“One moment, please...”
forexico.net — Контент недоступний (HTTP 502). Уособлення бренду: Genericcrypto; Тип шахрайства: Generic Phishing. Зведення доказів: VirusTotal 16/91 (ADMINUSLabs, alphaMountain.ai, BitDefender, Chong Lua Dao, CRDF); URLQuery 1 alert; URLScan malicious verdict; PhishDestroy score 100/100. Реєстратор: TuringSign.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
PhishDestroy identifies forexico.net as an active crypto drainer scam designed to trick users into connecting cryptocurrency wallets under the guise of a legitimate forex trading platform. The domain employs deception tactics commonly seen in financial scams, where victims are lured into interacting with fraudulent smart contracts that silently drain wallet funds. Technical analysis reveals that the domain resolves to IP 163.61.188.7, a hosting infrastructure previously associated with low-reputation activities. While the SSL certificate is issued by Let's Encrypt—often a misleading indicator of legitimacy—the domain’s recent creation date of November 12, 2025 (just days from now), combined with a registrar tied to TuringSign Inc. d/b/a Cosmotown, further underscores its suspicious nature. This domain exhibits multiple red flags consistent with emerging crypto scams. VirusTotal currently shows 5/95 detections—indicating that major antivirus engines have not yet flagged the domain, likely due to its recent deployment and use of obfuscated JavaScript payloads. The domain was registered through TuringSign Inc., a registrar known to facilitate bulk domain registrations with minimal verification, enabling threat actors to rapidly deploy fraudulent sites. The creation date is particularly alarming, as it suggests the scam site may be part of a coordinated campaign targeting unsuspecting traders during the holiday season. No blocklist entries have been recorded yet, likely because the domain is newly operational and has not yet been widely reported by victims. Users who accessed forexico.net or connected a wallet to the site should immediately disconnect their wallet from any dApps or websites and revoke any suspicious smart contract approvals. Transfer funds to a new wallet if funds are at risk, and consider using tools like revoke.cash to audit and revoke unauthorized token or NFT approvals. Monitor wallet activity closely and report any unauthorized transactions to local authorities or cybercrime units. Always verify URLs, use hardware wallets for sensitive transactions, and avoid interacting with unsolicited links in emails or social media.
Сигнали безпеки
Розвіддані з мережевої безпеки
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Private YARA rules | www.youtube.com/s/player/2d01abf7/player_embed_es6.vflset/en_us/base.js |
audit | Hunting_JS_WebAssembly |
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Збережений знімок
Аналітика доменів
Технічні деталіDNS, SAN-адреси SSL, мітки часу
ICANN OVERSIGHT
Акредитація та контекст RAA
Акредитація та контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Технології · 2 identified
Nginx is a web server that can also be used as a reverse proxy, load balancer, mail proxy and HTTP cache.
nginx.org 100% впевненостіOpenResty is a web platform based on nginx which can run Lua scripts using its LuaJIT engine.
openresty.org 100% впевненостіАналіз VirusTotal
Аналіз продуктивності сайту
Google PageSpeed Insights — mobile performance audit of forexico.net · checked May 14, 2026
Докази та зовнішні звіти
PD-20260514-16BFFC Recipient: abuse@whiteprivacy.com Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога