panedhkw[.]com
“Redirection”
PhishDestroy identifies panedhkw.com as a live cryptocurrency drainer site first catalogued under seed 805c4b. The domain masquerades as a benign redirect endpoint while surreptitiously loading malicious drainer kits aiming to empty victims’ digital wallets. No overt branding is leveraged, indicating a generic but highly targeted campaign against crypto users. The payload is delivered through a transparent redirection chain that terminates at the malicious endpoint hosted on 180.178.160.59. This domain was flagged by only 2 of 95 VirusTotal security vendors, underlines its stealthy deployment. Key technical indicators include registration via Hosting Concepts B.V. d/b/a Registrar.eu, a Let’s Encrypt SSL certificate for added legitimacy, an IP resolution to 180.178.160.59, and a creation timestamp of May 10, 2026. The domain carries no known presence in Google Safe Browsing and has not yet accrued mass blocklist coverage, enabling continued operation. As of today, panedhkw.com remains active and resolves to the malicious infrastructure. Immediate mitigation includes network-level blocking of both the domain and its resolving IP. Users should treat any interaction with this site as a high-risk cryptocurrency theft attempt. Remaining risk remains high while the domain continues to operate undetected by most vendors and blocklists.
Розвіддані з мережевої безпеки
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Cloudflare DNS | vos-passages-autoroutes.com |
malicious | Sinkholed |
| DNS4EU | vos-passages-autoroutes.com |
malicious | Sinkholed |
| Hagezi Threat Feed | vos-passages-autoroutes.com |
malicious | Sinkholed |
| OpenDNS | vos-passages-autoroutes.com |
phishing | Phishing Block |
| DigiCert UltraDNS | vos-passages-autoroutes.com |
malicious | Sinkholed |
Процес реагування на загрози Pipeline
Перевірка за блок-листами
10 джерел · синхронізовано 10.08.2026
Збережений знімок
Аналітика доменів
Технічні подробиціDNS, імена TLS і часові мітки
ICANN OVERSIGHT
Акредитація та контекст RAA
Акредитація та контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Технології
Виявлено 1 технологію з високою впевненістю
Аналіз VirusTotal
Аналіз продуктивності сайту
Google PageSpeed Insights — mobile performance audit of panedhkw.com · checked May 11, 2026
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога