opn-sea-lgn-welcom[.]pages[.]dev
“OpenSea Login | Your Secure Gateway to the NFT Marketplace”
opn-sea-lgn-welcom.pages.dev — Контент недоступний. Уособлення бренду: Across; Тип шахрайства: Crypto Drainer. Зведення доказів: VirusTotal 2/93 (ChainPatrol, Trustwave); Google Safe Browsing flagged; PhishDestroy score 80/100. Реєстратор: Cloudflare.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
The domain opn-sea-lgn-welcom.pages.dev was registered on February 21, 2026 through Cloudflare, Inc. and is currently taken offline, returning an HTTP 403 status. DNS resolution points to the IPv6 address 2606:4700:310c::ac42:2fb3, which is hosted by Cloudflare (AS13335) and geolocated to the United States. The authoritative nameservers are patrick.ns.cloudflare.com and emma.ns.cloudflare.com, indicating the use of Cloudflare’s DNS service. TLS termination is performed by a Google Trust Services certificate identified as WE1, confirming a legitimate‑looking HTTPS endpoint.
The site presented the page title "OpenSea Login | Your Secure Gateway to the NFT Marketplace," matching the known scam type of wallet/seed phishing targeting the OpenSea brand. Detection signals include a Gridinsoft trust score of 0 / 100, placement on a single security blocklist, and a Google Safe Browsing flag for social engineering. Two of ninety‑three VirusTotal scanners flagged the domain, and PhishDestroy has listed it as blocked. The overall risk level is elevated, reflecting the combination of brand impersonation and credential harvesting intent.
Uncertainty remains regarding the exact payload delivered to victims, as no additional forensic artifacts or malware hashes have been disclosed. Defenders should continue to block the domain at network perimeter devices, monitor for traffic to the associated Cloudflare IP range, and update URL filtering rules to include the full domain. Incident response teams receiving reports of compromised OpenSea credentials should verify against the domain’s creation timestamp and consider the possibility of seed phrase theft, applying standard remediation steps for wallet compromise.
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Криміналістичні дані
Аналіз VirusTotal
Аналіз продуктивності сайту
Google PageSpeed Insights — mobile performance audit of opn-sea-lgn-welcom.pages.dev · checked Mar 26, 2026
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога