MALICIOUS — CRITICAL
malgodex[.]io
malgodex.io operated as a phishing domain conducting brand impersonation of telegram.
- VirusTotal
- 4/91
- Blocklists
- No stored match
- Доступність
- Останній відомий активний · HTTP 301
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Notification and current-status evidence
The sent-report ledger records the first outgoing report at .
The recorded recipient is abuse@nicenic.net.
The latest stored availability evidence still shows the domain reachable; 6 months has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
Jump to section
malgodex.io — Останній відомий активний (HTTP 301). Уособлення бренду: Telegram; Тип шахрайства: Brand Impersonation. Зведення доказів: VirusTotal 4/91 (alphaMountain.ai, CRDF, Forcepoint ThreatSeeker, Gridinsoft); PhishDestroy score 76/100. Реєстратор: NiceNIC.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
Evidence Analysis
malgodex.io Phishing Intelligence Report - PhishDestroy
The domain malgodex.io, which impersonated Telegram, is currently down, suggesting a successful takedown.
malgodex.io operated as a phishing domain conducting brand impersonation of telegram. The site used a cryptocurrency exchange theme to target visitors through this scam tactic but has since been taken offline. Individuals searching for information on whether malgodex.io is safe will find it flagged as a malicious impersonation attempt.
Technical indicators show detection by 3 of 95 VirusTotal vendors including Fortinet, Gridinsoft, and SOCRadar. The domain was registered through NiceNIC International Group Co., Limited with a creation date of February 21, 2026 and resolved to IP address 172.67.210.238 under SSL issuer Google Trust Services / WE1. It appeared on 3 security blocklists including PhishDestroy, MetaMask, and SEAL while AlienVault OTX listed it in 1 threat intelligence pulse and Gridinsoft recorded a trust score of 0/100.
Users exposed to malgodex.io should change passwords for any associated accounts, enable 2FA, and monitor statements for signs of fraud. Report the incident to telegram support channels along with blocklist operators such as PhishDestroy to aid further mitigation efforts.
Stored source results
Recorded verdicts and infrastructure observations for this domain.
Обсяг даних12 recorded checks
Розвіддані з мережевої безпеки Registrar context
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Latest Classified Outcome 2026-08-09 02:46:57 UTC
Технології · 3 identified
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
Web infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
Аналіз VirusTotal
Архівні докази
Аналіз продуктивності сайту
Google PageSpeed Insights — mobile performance audit of malgodex.io · checked Apr 28, 2026
Докази та зовнішні звітиIndependent lookups and source reports
PD-20260127-425F0B Recipient: abuse@nicenic.net Victim safety and official reportingImmediate actions and verified reporting channels
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.