penpie-magpie[.]cc
“Magpie XYZ”
penpie-magpie.cc — Останній відомий активний (HTTP 302). Тип шахрайства: Generic Phishing. Зведення доказів: VirusTotal 4/94 (alphaMountain.ai, CyRadar, Forcepoint ThreatSeeker, Fortinet); PhishDestroy score 72/100. Реєстратор: NiceNIC.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
This domain is flagged as an elevated-risk phishing portal specifically designed to harvest cryptocurrency wallet credentials through fraudulent decentralized finance (DeFi) staking interfaces. Analysis indicates the site impersonates legitimate staking platforms to deceive users into connecting their wallets, enabling unauthorized fund transfers and private key exposure. Infrastructure analysis reveals multiple high-confidence threat indicators. The domain penpie-magpie.cc was registered on April 16, 2026, through NICENIC INTERNATIONAL GROUP CO., LIMITED, a registrar frequently associated with malicious domains. It resolves to IP address 188.114.97.3, which hosts multiple phishing sites targeting financial services. Security vendors on VirusTotal flagged the domain with 6/95 detections, confirming malicious intent. The domain appears on one security blocklist and was documented in a threat intelligence pulse on AlienVault OTX. Despite using a Google Trust Services SSL certificate, the site's infrastructure and behavioral patterns align with credential harvesting operations. Mitigation requires immediate action from both users and network defenders. Users who interacted with penpie-magpie.cc should revoke all connected wallet authorizations, rotate private keys, and monitor accounts for unauthorized transactions. Network administrators should implement DNS-based blocking of the domain and its associated IP address 188.114.97.3. Security teams should prioritize monitoring for connections to this infrastructure, particularly from endpoints that handle cryptocurrency transactions. Given the domain's current offline status, continuous monitoring is essential to detect potential re-emergence under similar naming conventions or infrastructure.
Розвіддані з мережевої безпеки Registrar context
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Збережений знімок
Аналітика доменів
Технічні деталіDNS, SAN-адреси SSL, мітки часу
Latest Classified Outcome 2026-08-14 02:45:53 UTC
Технології · 2 identified
Cloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com 100% впевненостіHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100% впевненостіАналіз VirusTotal
Архівні докази
Аналіз конфігурації сайту
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога