gifts-chainlink[.]org
“Salary.com | Compensation Data, Survey, Software & Analytics”
gifts-chainlink.org — Прикритий · доступний. Тип шахрайства: Credential Phishing. Зведення доказів: VirusTotal 10/91 (ADMINUSLabs, alphaMountain.ai, BitDefender, CRDF, CyRadar); Spamhaus DBL_PHISH; 2 external blocklist matches (MetaMask, SEAL); cloaking observed; PhishDestroy score 100/100. Реєстратор: NiceNIC.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
The domain gifts-chainlink.org is suspected of being involved in credential theft activities. This domain impersonates a well-known brand, Chainlink, to trick users into divulging their login credentials. The infrastructure analysis reveals that the domain is actively being used for phishing attacks, targeting individuals who may be unfamiliar with the legitimate Chainlink services.
Analysis indicates that the domain has a VirusTotal score of 0/95, suggesting it has not been flagged by the majority of security engines as of yet. The domain is registered through NICENIC INTERNATIONAL GROUP CO., LIMITED and resolves to the IP address 188.114.97.3. It was created on April 28, 2026. The domain is not currently listed in the Google Safe Browsing (GSB) database, and there are no known blocklist entries. The use of a Let's Encrypt SSL certificate provides an additional layer of trust that attackers are leveraging to appear more legitimate.
The current status of the domain is active, and it poses a significant risk to unsuspecting users. Immediate actions should include monitoring for any unauthorized access to accounts and educating employees or users about the risks of phishing through credential theft. Additionally, network administrators should consider blocking the IP address 188.114.97.3 and adding the domain to their internal threat lists to prevent further compromise. The remaining risk is high due to the domain's recent creation and lack of detection, making it a prime candidate for further investigation and potential mitigation.
Розвіддані з мережевої безпеки Registrar context
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Збережений знімок
Аналітика доменів
Технічні деталіDNS, SAN-адреси SSL, мітки часу
ICANN OVERSIGHT
Акредитація та контекст RAA
Акредитація та контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Latest Classified Outcome 2026-08-14 02:42:05 UTC
Аналіз VirusTotal
Архівні докази
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога