lineal2-network[.]xyz
lineal2-network.xyz — Неперевірений. Уособлення бренду: Linea; Тип шахрайства: Brand Impersonation. Зведення доказів: VirusTotal 2/95 (Gridinsoft, Trustwave); PhishDestroy score 56/100. Реєстратор: NiceNIC.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
lineal2-network.xyz was observed resolving to the Cloudflare edge address 104.21.82.175, which is announced by AS13335 in the United States. The domain was registered on 28 September 2025 through NiceNIC International Group Co., Limited and is served by the Cloudflare nameservers julissa.ns.cloudflare.com and tony.ns.cloudflare.com. No TLS certificate was presented during the brief connection attempt, and the HTTP response returned the generic title “Just a moment…”. VirusTotal records indicate that two of ninety‑five scanning engines flagged the domain as malicious, and the site appears on a single external blocklist.
PhishDestroy has also listed the domain as blocked. The infrastructure is classified as a brand‑impersonation campaign targeting the blockchain platform Linea, as indicated by the intelligence tag “Impersonates: Linea” and the scam type “Brand Impersonation”. The domain is currently reported as offline, which limits real‑time verification of the payload or credential‑harvesting mechanisms that may have been hosted. Consequently, the exact malicious content, redirect chains, or credential‑capture pages remain unknown.
Analysts should treat the domain as a potential threat vector until further evidence confirms its decommissioning. Defensive actions include adding the IP address 104.21.82.175 and the domain lineal2-network.xyz to network‑level deny lists, enforcing DNS filtering for the domain, and monitoring for any resurgence of the hostname or related Cloudflare‑hosted subdomains. Continuous observation of VirusTotal, blocklist feeds, and threat‑intelligence platforms is recommended to capture any future re‑activation. Because the registrar is NiceNIC International Group, investigators may consider requesting registration data to corroborate ownership and assess whether the domain is part of a broader malicious infrastructure.
Розвіддані з мережевої безпеки Registrar context
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Аналітика доменів
Технічні деталіDNS, SAN-адреси SSL, мітки часу
ICANN OVERSIGHT
Акредитація та контекст RAA
Акредитація та контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Latest Classified Outcome 2026-08-15 03:09:27 UTC
Аналіз VirusTotal
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога