MALICIOUS — CRITICAL
grabber[.]cy
16 of 91 security engines flagged the domain; 2 public blocklists listed it (MetaMask, SEAL); the latest stored check returned HTTP 502.
- VirusTotal
- 16/91
- Blocklists
- 2 · MetaMask, SEAL
- Доступність
- Контент недоступний · HTTP 502
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
grabber.cy — Контент недоступний (HTTP 502). Уособлення бренду: Binance; Тип шахрайства: Wallet/seed Phishing. Зведення доказів: VirusTotal 16/91 (ADMINUSLabs, alphaMountain.ai, BitDefender, Chong Lua Dao, CyRadar); URLQuery 3 alerts; Spamhaus DBL_MALWARE; 2 external blocklist matches (MetaMask, SEAL); CF Radar malicious; PhishDestroy score 95/100. Реєстратор: Ucy.ac.cy.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
Evidence Digest
grabber.cy is classified critical with an evidence score of 95/100. 16 of 91 security engines flagged the domain; 2 public blocklists listed it (MetaMask, SEAL). Registration metadata recorded via Ucy.ac.cy, hosted on 172.67.143.147 (CLOUDFLARENET - Cloudflare, Inc., US, US). The latest stored check on 9 Aug 2026 returned HTTP 502 and includes a capture. 1 outgoing abuse report is recorded, most recently on 14 Feb 2026.
Stored generated summary (templated)mistral · 23.07.2026
Retained for the record. This text repeats stored detection facts and is not presented as authored analysis.
Analysis of grabber.cy indicates a high-risk domain associated with a C++-based infostealer targeting cryptocurrency wallet credentials. The domain was registered on February 21, 2026, through Ucy.ac.cy and impersonates Binance, as confirmed by the page title 'TOK Grabber - Professional C++ Infostealer' and the scam classification 'Wallet/Seed Phishing.' Detection coverage is moderate: 14 of 91 security vendors on VirusTotal flagged the domain, and it appears on three security blocklists, including PhishDestroy, MetaMask, and SEAL. Gridinsoft assigns a trust score of 39/100, further supporting its malicious classification. Infrastructure analysis reveals the domain resolves to 172.67.143.147, hosted on Cloudflare's network (AS13335) in the US.
The site employs PHP, Tailwind CSS, and Cloudflare Browser Insights, with HTTP/3 support enabled. The SSL certificate is private, limiting further inspection. Nameservers include autumn.ns.cloudflare.com, cy-ns.anycast.pch.net, estia.ics.forth.gr, and ns31.rcode0.ne, suggesting a mix of commercial and academic DNS providers. As of July 23, 2026, the domain is offline, but historical evidence confirms its role in seed-phishing campaigns.
Defenders should treat this domain as confirmed malicious and prioritize blocking it at DNS and proxy layers. No additional payloads or lateral movement indicators are currently associated with this infrastructure. Further investigation into the C++ infostealer's distribution methods and command-and-control servers is recommended.
Обсяг даних13 recorded checks
Сигнали безпеки
Розвіддані з мережевої безпеки
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DigiCert UltraDNS | anondrop.net |
malicious | Sinkholed |
| Hagezi Threat Feed | anondrop.net |
malicious | Sinkholed |
| DNS4EU | anondrop.net |
malicious | Sinkholed |
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Технології · 5 identified
Cloudflare Browser Insights is a tool that measures the performance of websites from the perspective of users.
www.cloudflare.com 100% впевненостіCloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com 100% впевненостіHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100% впевненостіАналіз VirusTotal
Архівні докази
Аналіз продуктивності сайту
Google PageSpeed Insights — mobile performance audit of grabber.cy · checked Mar 2, 2026
Докази та зовнішні звітиIndependent lookups and source reports
PD-20260214-D5DC42 Recipient: christos@ucy.ac.cy Victim safety and official reportingImmediate actions and verified reporting channels
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.