Notification and current-status evidence
The sent-report ledger records the first outgoing report at .
The recorded recipient is abuse@dynadot.com.
The latest stored availability evidence still shows the domain reachable; 2 months has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
herostreetusa[.]org
“TronLink Wallet|TronLink web wallet”
herostreetusa.org — Прикритий · доступний. Тип шахрайства: Crypto Drainer. Зведення доказів: VirusTotal 14/91 (ADMINUSLabs, alphaMountain.ai, Chong Lua Dao, CRDF, CyRadar); URLQuery 2 alerts; 2 external blocklist matches (MetaMask, SEAL); CF Radar malicious; cloaking observed; PhishDestroy score 95/100. Реєстратор: Dynadot.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
This domain, herostreetusa.org, operates as a crypto wallet drainer designed to steal credentials and exfiltrate digital assets from unsuspecting users. Analysis indicates the site mimics legitimate cryptocurrency platforms, tricking victims into entering private keys or wallet recovery phrases. Once obtained, these credentials are used to drain funds from connected wallets, resulting in irreversible financial losses. The threat specifically targets users of decentralized finance (DeFi) platforms and non-custodial wallets, exploiting the irreversible nature of blockchain transactions to maximize impact. Infrastructure analysis reveals multiple high-risk indicators. The domain was registered on June 08, 2026, through Dynadot Inc, a registrar frequently associated with malicious activity. It resolves to the IP address 188.114.96.3 and is flagged by 14 out of 95 security vendors on VirusTotal. Additionally, herostreetusa.org appears on three security blocklists and has been proactively blocked by multiple threat intelligence platforms. The domain’s SSL certificate, issued by Let’s Encrypt, does not mitigate its malicious intent, as attackers commonly use valid certificates to appear legitimate. Users who visited herostreetusa.org or interacted with its content should immediately disconnect any connected wallets from the internet and transfer remaining assets to a new, secure wallet. Monitor all linked accounts for unauthorized transactions and revoke any suspicious smart contract approvals using a blockchain explorer. If credentials were entered, assume they are compromised and avoid reusing them. Report the incident to relevant financial or cryptocurrency platforms to assist in tracking the threat. Regularly update security tools and enable multi-factor authentication on all critical accounts to prevent future exploitation.
Розвіддані з мережевої безпеки
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Збережений знімок
Аналітика доменів
Технічні деталіDNS, SAN-адреси SSL, мітки часу
ICANN OVERSIGHT
Акредитація та контекст RAA
Акредитація та контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Технології · 2 identified
Cloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com 100% впевненостіHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100% впевненостіАналіз VirusTotal
Докази та зовнішні звіти
PD-20260608-D70BAB Recipient: abuse@dynadot.com Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога