monad[.]dexorlab[.]xyz
“רק רגע...”
monad.dexorlab.xyz — Неперевірений. Уособлення бренду: Monad; Тип шахрайства: Brand Impersonation. Зведення доказів: VirusTotal 4/95 (ChainPatrol, CyRadar, Forcepoint ThreatSeeker, SOCRadar); PhishDestroy score 65/100. Реєстратор: NiceNIC.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
The domain monad.dexorlab.xyz was registered on November 16, 2025 through NiceNIC International Group Co., Limited and is currently resolved to the Cloudflare address 172.67.167.21, belonging to ASN 13335 in the United States. Its authoritative nameservers are huxley.ns.cloudflare.com and katelyn.ns.cloudflare.com, indicating the use of Cloudflare’s DNS and edge services. No SSL certificate is presented for the site, so any HTTP connection would be unsecured.
The page title returned by the server is the Hebrew phrase "רק רגע...", which translates to "Just a moment..."; no further content has been captured because the site is presently taken offline. Four of ninety‑five VirusTotal scanners flagged the domain, and it appears on a single external security blocklist, with PhishDestroy confirming the domain as blocked for brand impersonation of Monad. The observed infrastructure—Cloudflare edge hosting, lack of TLS, and a minimal page title—matches patterns commonly employed in short‑lived brand‑impersonation campaigns that rely on rapid DNS redirection and content replacement.
Because the domain is inactive, immediate mitigation focuses on ensuring that network perimeter controls block both the domain name and its resolved IP address, and that security appliances update their threat feeds to include the listed blocklist entry. Continuous monitoring of the domain’s DNS records is advised, as the operator could reactivate the site or repoint it to new malicious payloads. Defenders should also consider adding the registrar NiceNIC International Group Co., Limited to watch‑lists for future registrations that may target the same brand, and verify that any user‑facing services referencing Monad enforce strict TLS validation to prevent credential capture should the domain become active again.
Розвіддані з мережевої безпеки Registrar context
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Збережений знімок
Аналітика доменів
Технічні деталіDNS, SAN-адреси SSL, мітки часу
ICANN OVERSIGHT
Registration: dexorlab.xyz
Акредитація та контекст RAA
Акредитація та контекст RAA
Registrar accreditation and DNS abuse obligations
For the registrable domain dexorlab.xyz behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Latest Classified Outcome 2026-08-05 18:28:30 UTC
Аналіз VirusTotal
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога