MALICIOUS — CRITICAL
Перевірка домену mobichain.co на фішинг і безпеку
mobichain[.]
Analysis of mobichain.co indicates that the domain is being used for a phishing operation targeting users interested in cryptocurrency bill‑splitting services.
- VirusTotal
- 3/91
- Blocklists
- No stored match
- Доступність
- Останній відомий активний · HTTP 200
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Notification and current-status evidence
The sent-report ledger records the first outgoing report at .
The recorded recipient is abuse@dynadot.com.
The latest stored availability evidence still shows the domain reachable; 13 days has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
Jump to section
mobichain.co — Останній відомий активний (HTTP 200). Зведення доказів: VirusTotal 3/91 (CRDF, Gridinsoft, SOCRadar); PhishDestroy score 76/100. Реєстратор: Dynadot.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
Evidence Analysis
Analysis of mobichain.co indicates that the domain is being used for a phishing operation targeting users interested in cryptocurrency bill‑splitting services. The site is registered through Dynadot Inc and was created on 26 June 2025. It resolves to the Cloudflare edge address 172.67.177.29 and uses the Cloudflare nameservers ingrid.ns.cloudflare.com and kipp.ns.cloudflare.com, suggesting the infrastructure is hosted behind a CDN. The page title returned from the live site reads "Mobichain – Split Bills & Pay Instantly with Crypto," which aligns with the reported phishing theme.
The domain has been blocked by the PhishDestroy feed and appears on one external security blocklist, confirming that at least one reputable source has identified it as malicious. VirusTotal records show that the domain was scanned by 91 AV engines, none of which raised a detection; however, the absence of detections does not constitute evidence of safety and should be weighed against the other indicators. No additional intelligence such as OTX references, SSL certificate details, HTTP response codes, or trust‑score metrics is available at this time. The current risk level remains under investigation, and the site is still active.
Defenders should add mobichain.co to web‑filter deny lists, monitor DNS queries for the domain, and block outbound connections to the associated IP address. Since the domain leverages Cloudflare, traffic may be distributed across multiple edge nodes, so broader IP range monitoring may be required. Continuous re‑evaluation is advised as further telemetry becomes available.
Stored source results
Recorded verdicts and infrastructure observations for this domain.
Обсяг даних13 recorded checks
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Технології · 5 identified
Webflow is Software-as-a-Service (SaaS) for website building and hosting.
webflow.com 100% впевненостіSmartsupp is a live chat tool that offers visitor recording feature.
www.smartsupp.com 100% впевненостіCloudflare Browser Insights is a tool that measures the performance of websites from the perspective of users.
www.cloudflare.com 100% впевненостіCloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com 100% впевненостіHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100% впевненостіАналіз VirusTotal
Архівні докази
Аналіз продуктивності сайту
Google PageSpeed Insights — mobile performance audit of mobichain.co · checked Jul 27, 2026
Докази та зовнішні звітиIndependent lookups and source reports
“I was contacted through the Instagram account @tradeemomentumm and later through WhatsApp by an individual using the name "Momentum." I was persuaded to invest in cryptocurrency through the website digitalassetsautomation.net. On 5 June 2026, I transferred 0.01869529 BTC from my verified Binance account to the following Bitcoin address: bc1qjjxur2qv82w3ngyx852hv8v9ln43hwtzarm47l Transaction Hash (TXID): 734b3adc28fcee755fcf313b6f903ba7acd7a7d4b6fcd0ef4743d21ad119174d After the tra”
PD-20260727-83399D Recipient: abuse@dynadot.com Victim safety and official reportingImmediate actions and verified reporting channels
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.