VirusTotal
12 / 91
“MQL5 Forex: Expert Advisors & Automated Trading Bots for MT4/MT5”
mql5.software — Контент недоступний. Тип шахрайства: Investment Scam. Зведення доказів: VirusTotal 12/91 (ADMINUSLabs, alphaMountain.ai, BitDefender, Chong Lua Dao, ESET); PhishDestroy score 86/100. Реєстратор: Ultahost.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
12 / 91
checked — no detections recorded
Повідомитиchecked — no match recorded
no community references
Повідомитиprovider verdict: clean
Повідомитизбережений звіт
Повідомити 14 перевірено — блокувань немає
Checked; no threat flag recorded
ПовідомитиThe domain mql5.software was a generic phishing site posing as an investment scam related to forex trading and automated bots for MT4/MT5 platforms. It did not impersonate a specific legitimate brand but used the MQL5 name to deceive users into believing it offered expert advisors or trading tools. The site has since been taken offline, but it previously presented an elevated risk of financial fraud or credential theft.
Technical indicators show mql5.software was flagged by 2 of 95 VirusTotal security vendors and appeared on 1 security blocklist (PhishDestroy). The domain was registered through Ultahost, Inc on June 05, 2024, and resolved to the IP address 82.41.181.74, located in the United Kingdom. It used Cloudflare nameservers (ignacio.ns.cloudflare.com and ivy.ns.cloudflare.com) and had an SSL certificate issued by Let's Encrypt. The observed page title was 'MQL5 Forex: Expert Advisors & Automated Trading Bots for MT4/MT5,' and technologies detected included Node.js, Ubuntu, React, Nginx, Next.js, Google Analytics, and Webpack. Gridinsoft assigned it a trust score of 0/100.
Users who interacted with mql5.software should monitor their accounts for unauthorized transactions, particularly if financial or login credentials were entered. Change passwords for any accounts accessed through the site and enable two-factor authentication where available. Report the domain to relevant authorities or platforms, such as the registrar (Ultahost, Inc), Google Safe Browsing, or local cybercrime units. If cryptocurrency was involved, review wallet approvals and consider moving funds to a new wallet to prevent further exposure.
Full extracted values, their blockchain and collection source. An address found in page content does not establish who controls it.
https://t.me/yoforexrobotStored page referencehttps://t.me/+eo74nsL9xXI1YTFlStored page referencehttps://t.me/+nD3WKXYKahwyNzE1Stored page referencehttps://t.me/+t4vLn-yl8mcxYTU1Stored page referencehttps://t.me/YoForexAsia/Stored page referenceIoC extraction recorded 2026-07-29 02:25:25 UTC
Збережені дані спостережень за взаємодією веб-сканера та браузера для цього хоста, а також перевірка відбитків у режимі реального часу для систем розподілу трафіку типу «Кейтаро».
Примітка щодо сканера: unavailable: raw=connection_error; http=0; via=http_proxy; error=SOCKSHTTPConnectionPool(host='mql5.software', port=80): Max retries exceeded with url: / (Caused by NewConnectionError("
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Репутація Edge-IP не пов’язана з цим доменом.
ignacio.ns.cloudflare.comivy.ns.cloudflare.comLocation describes the IP network.
Saved certificate metadata. Certificate dates without a timezone are shown as stored. Transport encryption does not establish that the site is trustworthy.
Google PageSpeed Insights — mobile performance audit of mql5.software · checked Mar 18, 2026
11 recorded events. These records describe collected evidence, outgoing notifications and publication; they do not confirm a complete investigation or a takedown.
We scan suspicious URLs, inspect public results and send evidence through the appropriate abuse-reporting channels. The dated events above show what is recorded for this domain. The directory below explains the wider workflow.
Capture the rendered page, requests and visible infrastructure.
Compare the available engine results and retain the analysis timestamp.
Check whether Google currently lists the URL as unsafe.
Inspect a public scan and its recorded network and classification data.
Look for indicator references and related community intelligence.
Compare archived captures and preserve historical context.
Look for matching indicators and associated threat records.
Inspect certificate records and related hostnames.
Compare security resolver responses and record observed blocking.
Inspect the public DNS, TLS, HTTP and technology surface.
Security services used for scanning, reputation checks and reporting are listed below. A service being listed is not evidence that it received, accepted or acted on this particular domain. Recorded submissions appear in the notification history above.
Повідомив 1 учасник спільноти; уперше помічено 18.03.2026
PD-20260318-67ADF2 Recipient: u-abue@ultahost.com Policy Violations: Acceptable Use Policy (AUP): The domain mql5.software is engaged in phishing activities, which constitutes a direct violation of your AUP prohibiting illegal activities, fraud, and deception. Terms of Service (TOS): The continued operation of this domain violates your TOS, which reserves the right to suspend or terminate services for any activities that are illegal or harmful to users. Applicable Laws (Unknown): Computer Fraud and Abuse Act (CFAA): This U.S. law prohibits unauthorized access to computers and networks, including phishing schemes that deceive users into providing sensitive information. Wire Fraud Statute (18 U.S.C. § 1343): This law addresses fraudulent schemes that involve interstate wire communications, which is applicable to phishing operations that deceive individuals for financial gain. CAN-SPAM Act (15 U.S.C. § 7701): This act regulates commercial email and prohibits deceptive practices in electronic communications, which includes phishing attempts. Regulatory Note: Failure to take immediate action against this domain may expose your organization to legal liability and regulatory scrutiny. Non-compliance with your own policies and applicable laws could result in significant penalties.
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Template-based draft · optional AI wording assistance requires separate consent
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразДодавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиОстанні звіти про фішинг і помічені зміни доступності
ВідстежуватиСлідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога