MALICIOUS — CRITICAL
Перевірка домену hickory.website на фішинг і безпеку
hickory[.]
This domain, hickory.website, was identified as a high-risk crypto scam impersonating Binance, with infrastructure analysis confirming its malicious intent prior to being taken offline.
- VirusTotal
- 10/93
- Blocklists
- 3 · Polkadot, Enkrypt
- Доступність
- Контент недоступний · HTTP 502
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
hickory.website — Контент недоступний (HTTP 502). Уособлення бренду: Binance; Тип шахрайства: Crypto Scam. Зведення доказів: VirusTotal 10/93 (ADMINUSLabs, alphaMountain.ai, BitDefender, CRDF, CyRadar); URLScan malicious verdict; 3 external blocklist matches (Polkadot, Enkrypt, Codeesura); PhishDestroy score 80/100.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
Evidence Analysis
This domain, hickory.website, was identified as a high-risk crypto scam impersonating Binance, with infrastructure analysis confirming its malicious intent prior to being taken offline. Registered on February 21, 2026, the domain resolved to IP 66.29.146.168, hosted on AS22612 (Namecheap, Inc.) in the United States. The SSL certificate, issued by Sectigo Public Server Authentication CA (DV R36), provided no additional trust signals, as Domain Validation certificates are routinely abused in phishing campaigns. The page title, 'TRON Wallet Integration Example,' suggests the scam targeted users of TRON-based cryptocurrency wallets, aligning with the broader pattern of Binance brand impersonation for fraudulent crypto transactions. Security vendors and blocklists flagged the domain aggressively: PhishDestroy, Polkadot, Enkrypt, and Codeesura all blocked it, and it appeared on four independent security blocklists.
While VirusTotal recorded 10 detections out of 93 vendors, this partial coverage is consistent with domains that evade initial scans or are reported after partial exposure. Gridinsoft assigned a trust score of 0/100, reinforcing its classification as malicious. No evidence links this domain to a known phishing kit, and the exact content beyond the page title remains unanalyzed due to its offline status. Defenders should treat this domain as confirmed malicious infrastructure. The IP (66.29.146.168) and hosting provider (Namecheap) are recurrent in phishing operations, warranting monitoring for re-registration or IP reuse.
The SSL issuer (Sectigo) is not inherently suspicious, but the DV certificate type offers no organizational validation. Given the domain’s short lifespan and rapid takedown, it likely operated as part of a larger campaign; defenders should cross-reference the IP, registrar, and brand impersonation (Binance) in logs for related activity. No Safe Browsing or OTX data was provided, so additional context on distribution methods (e.g.
Stored source results
Recorded verdicts and infrastructure observations for this domain.
Обсяг даних12 recorded checks
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Криміналістичні дані
Аналіз VirusTotal
Докази та зовнішні звітиIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.