Перейти до звіту про безпеку
⚠️
Цей домен було позначено як шкідливий
Системи безпеки повідомляють про виявлення: 2. Публічні списки блокувань, які повідомляють про збіг: 1. Будьте дуже обережні — не вводьте облікові дані чи особисту інформацію.
Безпека домену та аналіз загроз

moltchecker[.]org

“X. It’s what’s happening / X”

Загрозливий вердикт Критичний 71/100 оцінка доказів
Доступність Прикритий · доступний Доступність спостерігається за допомогою перевірок маскування
Виявлення VirusTotal: 2/94 Збережений список блокувань відповідає: 1 URLQuery threat systems: 1 alert Уособлення бренду: Apple Останній відомий активний
29.03.2026 Apple 1 Report Sent CDN

Збережене виявлення

Виявлено маскування

Тип маскування
bot_redirect_safe
Оцінка маскування
4/6
Зведення доказів
КРИТИЧНИЙ
Оцінка
71/100

The domain moltchecker.org has been identified as an active generic phishing site, specifically functioning as a cryptocurrency drainer designed to deceive users into connecting their crypto wallets under the guise of a legitimate service. This threat vector is particularly dangerous as it targets users' digital assets by tricking them into authorizing unauthorized transactions. The page impersonates Molotov TV, a well-known streaming platform, leveraging its branding to gain user trust before executing its malicious payload. The fraudulent site is engineered to detect crypto wallet connections and automatically drain funds upon authorization, posing a severe financial risk to unsuspecting visitors.

Forensic analysis of moltchecker.org reveals critical technical indicators that confirm its malicious nature. The domain was registered on March 20, 2026, through PDR Ltd. d/b/a PublicDomainRegistry.com, a registrar frequently abused in bulk phishing campaigns. It resolves to the IP address 188.114.97.3, which is associated with previous malicious activities. The SSL certificate, issued by Let's Encrypt, provides a false sense of security, as phishing sites often use legitimate certificates to appear trustworthy. VirusTotal currently reports 2 out of 95 detection engines flagging this domain, highlighting its stealthy nature and the need for proactive threat intelligence. Additionally, the domain has been listed on one security blocklist, though this is likely an underrepresentation due to the recent registration and low detection rates. Google Safe Browsing (GSB) does not currently flag this domain, further emphasizing the challenge in identifying such emerging threats.

The current status of moltchecker.org is active and under investigation, with the domain remaining accessible at the time of this report. PhishDestroy and ScamSniffer have already implemented blocking mechanisms to protect users, but the domain's low detection rate on VirusTotal suggests that broader ecosystem awareness is still lacking. The primary risk associated with this site is financial loss, particularly for users who connect their crypto wallets without verifying the site's legitimacy. To mitigate risk, users should avoid interacting with this domain entirely and verify the safety of any related domains or services through PhishDestroy's threat intelligence platform. Remaining risk is considered moderate due to the domain's recent deployment and limited blocklist coverage, but it has the potential to escalate rapidly as attackers refine their tactics. Security researchers are encouraged to monitor this domain closely for updates, as the lack of detections may indicate either a very new campaign or the use of sophisticated evasion techniques.

Запис надісланого повідомлення

Знімок надісланих доказів

Надіслано
Записи журналу
1
ID справи
PD-20260329-E35A01
Заголовок збереженої сторінки
x.com/
PDF-файл
PDF із доказами
Повний текст доказів
Policy Violations:
Illegal Activities: Active phishing operation targeting victims
Fraud & Deception: Impersonation of legitimate services
Identity Theft: Collection of credentials under false pretenses
Applicable Laws (Unknown):
International Anti-Cybercrime Regulations
Budapest Convention on Cybercrime
Universal Fraud Prevention Laws
Phishing activities violate international cybercrime conventions and Unknown's domestic fraud laws.
Action Required: This evidence-backed report demonstrates clear violations requiring suspension per your policies. Continued hosting exposes your organization to regulatory scrutiny and potential legal liability.
VirusTotal
VirusTotal
2 det.
URLQuery
URLQuery
1 threat alert
DNS Security
3/12
Сертифікат TLS
Let's Encrypt
Вік
4 mo
Зафіксований статус
Прикритий · доступний 502
PhishDestroy
DestroyList
У списку
Reports Sent
1
Обсяг даних VirusTotal 2 / 94 URLQuery 1 threat-system alert PhishStats checked — no match recorded OTX no community references CF Radar scan completed URLScan capture збережений звіт URLScan verdict Аналіз завершено Блокування DNS 3/12 TLS valid certificate, 80d WHOIS 4 mo old Знімок екрана 3 captures · 3 sources Ланцюжок перенаправлень не досліджено
Розвіддані з мережевої безпеки
DNS Provider Blocks 3 / 12
Controld Adblock Controld Family Controld Malware
Threat Detection Systems 1 alert
Detection System Indicator Verdict Alert
Hagezi Threat Feed moltchecker.org malicious Sinkholed

Процес реагування на загрози Pipeline

Відкриття
Checks
Reports
Доступність
13/14

Перевірка за блок-листами

Джерел: 10 · синхронізовано 10.08.2026

Збережений знімок

Заголовок сторінки
X. It’s what’s happening / X
Impersonates
Apple Google
Сертифікат TLS
Valid transport encryption · Виданий Let's Encrypt · valid for 80 days

Аналітика доменів

Домен
URLScan Verdict Аналіз завершено score 0 report ↗
Сервер / ASN cloudflare envoy · AS13335 Cloudflare, Inc.
IP Context Cloudflare shared edge origin IP hidden Репутація Edge-IP не пов’язана з цим доменом.
Реєстратор PDR IN(IN)
IP-адреса 188.114.97.3 CDN
ГеолокаціяCA Toronto, CA
МережаAS13335 · CloudFlare, Inc.
Зворотний пошук IPviewdns.info → rapiddns.io →
Початкова IP-адреса прихована за проксі CDN. Результати зворотного IP для крайової адреси містять непов’язаних орендарів; для пошуку джерела потрібен пасивний DNS або дані прозорості сертифіката.
РеєстраціяСтворено 29.03.2026 (133d)
Статус HTTP502 Error
Elapsed Since First Report 25 days
Що ми враховуємо Raw elapsed time since the first stored abuse report. It is not a registrar response-time measurement. Latest observed status: Прикритий · доступний.
Що містить кожен звіт Збережені записи вихідних звітів можуть посилатися на докази, доступні на той час, наприклад вердикти постачальників, реєстраційні дані, деталі хостингу, класифікації або знімки екрана. Ця сторінка не визначає точного доставленого корисного навантаження, квитанції, підтвердження чи дії одержувача.
Технічні подробиціDNS, імена TLS і часові мітки
Вперше виявлено29.03.2026
DOM Analysisanalyzed 29.07.2026score 71/1002 brand signals
Submitted URLhttp://moltchecker.org/
Сервери іменlynn.ns.cloudflare.com
Спостереження TLSперевірено 17.05.2026
ICANN OVERSIGHT

Акредитація та контекст RAA

Registrar accreditation and DNS abuse obligations

For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.

Accreditation is a contract, not a safety certification.

RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.

Accountability draft Нічого не надсилається автоматично.
Поскаржитися на цей домен Надішліть докази та допоможіть захистити інших

Аналіз VirusTotal

2 / 94 постачальників безпеки позначили цей домен
View on VT
Last analyzed
Gridinsoft
Seclookup

Чи вплинув на вас цей сайт?

If credentials were compromised, report immediately. Do not engage with recovery scammers.

Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.

Європол
Знайдіть офіційний канал звітності для вашої країни ЄС
National police directory
Остерігайтеся шахраїв, які обіцяють повернути втрачені кошти! Злочинці можуть знову зв’язатися з жертвами, видаючи себе за слідчих, адвокатів або агентів із відновлення. Не сплачуйте авансових зборів і не діліться обліковими даними. Дізнайтеся більше про шахрайство у сфері відшкодування збитків →

Зверніться до місцевих органів влади

Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.

Довідник 97 країн
Чернетка за допомогою штучного інтелекту — деталі інциденту обробляються постачальником штучного інтелекту Перегляньте та подайте його самостійно

Перевірити будь-який домен

Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування

Сканувати зараз

Повідомити про фішинг

Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту

Повідомити

Потокова стрічка про загрози

Останні звіти про фішинг і помічені зміни доступності

Відстежувати

Будьте в курсі подій, дбайте про свою безпеку

Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога

Потокова стрічка про загрози Оскаржити це оголошення

Зовнішні інструменти

HTML · IFRAME

Вбудувати цей звіт

Поділіться цією інформацією про загрози на своєму веб-сайті або в блозі

embed.html
<iframe
  src="https://phishdestroy.io/uk/embed/domain/moltchecker.org"
  title="PhishDestroy threat report for moltchecker.org"
  width="100%" height="320"
  loading="lazy"
  referrerpolicy="no-referrer"
  sandbox="allow-same-origin allow-popups allow-popups-to-escape-sandbox"
  style="border:0;border-radius:12px;max-width:100%"
></iframe>

Дуже щирий лист-подяка

Генератор сатиричних чернеток

Одержувач
Контекст зборів

Це сатирична чернетка. Суми зборів є оцінками; ми не стверджуємо, що вони точно стосуються цього домену.