Notification and current-status evidence
The sent-report ledger records the first outgoing report at .
The recorded recipient is domainabuse@tucows.com.
The latest stored availability evidence still shows the domain reachable; 3 months has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
monerogui[.]com
Перевірка домену monerogui.com на фішинг і безпеку
“Monero GUI wallet | Download Monero GUI Wallet |”
monerogui.com — Останній відомий активний (HTTP 200). Тип шахрайства: Crypto Drainer. Зведення доказів: VirusTotal 3/91 (CRDF, Gridinsoft, SOCRadar); 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 78/100. Реєстратор: TUCOWS.COM, CO.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
PhishDestroy identifies monerogui.com as an active Monero-draining phishing site under investigation as of seed 2512f8. The domain shows no affiliation with legitimate Monero projects and employs a generic but deceptive naming convention to lure victims. While no specific drainer kit was detected during initial analysis, the site’s structure and recent creation suggest it is likely utilizing a kit or custom script to facilitate unauthorized Monero transactions.
This domain was flagged with a VirusTotal detection score of 0 out of 95 engines, indicating it remains undetected by most antivirus solutions. It was registered through TUCOWS.COM, CO., resolving to IP address 69.10.36.99 and secured with a Let’s Encrypt SSL certificate. The domain was created on October 07, 2025, and has not yet been listed on Google Safe Browsing (GSB) or other major blocklists, leaving potential victims exposed.
As of now, monerogui.com remains active and poses a moderate risk to cryptocurrency users. Immediate actions include blocking the domain at the network perimeter, updating firewall rules to include IP 69.10.36.99, and distributing IOCs to threat intelligence platforms. Users are advised to avoid interacting with the site and to verify cryptocurrency-related domains through official channels. The remaining risk is classified as active but under investigation, with further analysis pending additional telemetry.
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Збережений знімок
Аналітика доменів
Технічні деталіDNS, SAN-адреси SSL, мітки часу
ICANN OVERSIGHT
Акредитація та контекст RAA
Акредитація та контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Технології · 2 identified
Nginx is a web server that can also be used as a reverse proxy, load balancer, mail proxy and HTTP cache.
nginx.org 100% впевненостіOpenResty is a web platform based on nginx which can run Lua scripts using its LuaJIT engine.
openresty.org 100% впевненостіАналіз VirusTotal
Аналіз продуктивності сайту
Google PageSpeed Insights — mobile performance audit of monerogui.com · checked May 1, 2026
Докази та зовнішні звіти
PD-20260501-0216EC Recipient: domainabuse@tucows.com Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога