Notification and current-status evidence
The sent-report ledger records the first outgoing report at .
The recorded recipient is abuse@dynadot.com.
The latest stored availability evidence still shows the domain reachable; 3 months has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
nodebridge[.]host
Перевірка домену nodebridge.host на фішинг і безпеку
“BAYKAR AYDA 200.000 LİRA ÖDÜYOR! BU FIRSATI KAÇIRMAYIN! BAYKAR PROGRAMINA ...”
nodebridge.host — Помилка сервера (HTTP 502). Уособлення бренду: Facebook; Тип шахрайства: Crypto Drainer. Зведення доказів: VirusTotal 18/91 (ADMINUSLabs, alphaMountain.ai, BitDefender, Chong Lua Dao, CRDF); PhishDestroy score 95/100. Реєстратор: Dynadot.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
PhishDestroy identifies nodebridge.host as an active crypto-draining phishing domain currently under investigation for hosting fraudulent cryptocurrency wallet drainer pages. This malicious domain mimics legitimate crypto-bridge services to trick users into connecting crypto wallets under the guise of processing transactions. The campaign is designed to silently drain victim wallets of all tokens and NFTs without requiring explicit authentication once the wallet is linked.
This domain was flagged by zero out of ninety-five VirusTotal vendors as of the latest scan, indicating a currently undetected threat. nodebridge.host resolves to IP 188.114.97.3 and was registered through Dynadot Inc on December 19, 2025. The domain holds a valid SSL certificate issued by Google Trust Services, which may contribute to a false sense of legitimacy. Despite zero detections on VirusTotal, the lack of historical reputation and absence from mainstream blocklists such as Google Safe Browsing and OpenPhish suggests this domain is extremely recent and potentially part of a fast-moving, short-lived campaign targeting crypto users.
Given the domain’s active status and the significant risk it poses to cryptocurrency users, immediate defensive action is recommended. Users are advised to avoid interacting with nodebridge.host or any subdomains. Blocklists should be updated to include this domain and associated IP address (188.114.97.3) at the network perimeter and endpoint level. Additionally, cryptocurrency wallet users should be notified to verify any domain linking their wallet by cross-referencing with official sources via PhishDestroy or similar threat intelligence platforms. Continuous monitoring for related infrastructure is warranted due to the potential for rapid expansion through newly registered domains leveraging similar naming conventions.
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Збережений знімок
Аналітика доменів
Технічні деталіDNS, SAN-адреси SSL, мітки часу
ICANN OVERSIGHT
Акредитація та контекст RAA
Акредитація та контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Технології · 9 identified
Server-side scripting language designed for web development.
Popular CSS framework for responsive, mobile-first web development.
JavaScript library for building user interfaces with component-based architecture.
Free public CDN for open-source projects, serving files from npm and GitHub.
Fast, small JavaScript library simplifying HTML manipulation, event handling, and Ajax.
Conversion-tracking pixel by Meta — logs page views and custom events to Facebook/Instagram ad accounts.
www.facebook.comWeb infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
Аналіз VirusTotal
Аналіз продуктивності сайту
Google PageSpeed Insights — mobile performance audit of nodebridge.host · checked Apr 15, 2026
Докази та зовнішні звіти
PD-20260415-8E4CC7 Recipient: abuse@dynadot.com Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога