lfg-traderjoexyz[.]net
“www.www.lfg-traderjoexyz.net”
lfg-traderjoexyz.net — Останній відомий активний (HTTP 302). Тип шахрайства: Fake Exchange. Зведення доказів: VirusTotal 4/91 (alphaMountain.ai, CRDF, Gridinsoft, SOCRadar); PhishDestroy score 72/100. Реєстратор: NiceNIC.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
PhishDestroy identifies lfg-traderjoexyz.net as a generic phishing domain impersonating Trading Joe's X cryptocurrency platform to harvest user credentials. The domain leverages a deceptive subdomain structure (www.www.lfg-traderjoexyz.net) to appear legitimate, targeting individuals seeking crypto trading opportunities. Technical analysis confirms this is an active phishing attempt with no current blocklist presence, underscoring the need for immediate user vigilance.
This domain was flagged on April 15, 2025, through NICENIC INTERNATIONAL GROUP CO., LIMITED, resolving to IP 188.114.97.3. VirusTotal currently shows 4/95 detections, indicating undetected malicious activity. The domain utilizes a Google Trust Services SSL certificate, further enhancing its deceptive legitimacy. Despite its recent creation and low detection profile, the threat level remains under investigation due to the high-risk nature of phishing campaigns targeting financial platforms. No prior associations with known threat actors or historical blocklist entries were detected at the time of analysis.
Mitigation requires immediate avoidance of the domain and any associated subdomains. Users should verify the authenticity of trading platforms through official channels and report suspicious domains to cybersecurity teams. Financial institutions and crypto platforms must monitor this IP range for related activities. Security researchers are advised to track the SSL certificate and registrar patterns for potential broader campaigns. Proactive user education on credential hygiene and multi-factor authentication remains critical to mitigating phishing risks.
Розвіддані з мережевої безпеки Registrar context
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Збережений знімок
Аналітика доменів
Технічні деталіDNS, SAN-адреси SSL, мітки часу
ICANN OVERSIGHT
Акредитація та контекст RAA
Акредитація та контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Latest Classified Outcome 2026-08-13 02:44:10 UTC
Криміналістичні дані
Аналіз VirusTotal
Архівні докази
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога