polkadot[.]fi
“polkadot.fi is available for purchase - Sedo.com”
polkadot.fi — Неперевірений. Зведення доказів: VirusTotal 5/91 (ChainPatrol, alphaMountain.ai, Chong Lua Dao, Forcepoint ThreatSeeker, Gridinsoft); 3 external blocklist matches (Polkadot, Enkrypt, Codeesura); PhishDestroy score 85/100. Реєстратор: Hosting Concepts.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
polkadot.fi is currently flagged as a high‑risk generic phishing domain. The zone was created on 10 November 2023 and is registered through Hosting Concepts B.V. d/b/a Registrar.eu. DNS resolution points to 104.16.140.114, an IP owned by Cloudflare, Inc. (AS13335) located in the United States. The service presents a valid TLS certificate issued by Let’s Encrypt (E7), and the server responds with HTTP 200, employing Google Analytics and HTTP/3. Infrastructure analysis shows the domain is listed on four independent blocklists—PhishDestroy, Polkadot, Enkrypt, and Codeesura—and appears on a total of four security blocklists. On VirusTotal, four of ninety‑five scanning engines raised detections for the domain, while the Gridinsoft trust score registers at the lowest possible value, 0 / 100. The public page title reads “polkadot.fi is available for purchase – Sedo.com”, indicating the domain is currently parked. The observed evidence confirms the domain’s active malicious status, yet several operational details remain unclear. No nameserver information is available, and the exact payload or phishing kit hosted behind the domain has not been observed. Consequently, the specific techniques employed to harvest credentials or redirect victims cannot be described, and the presence of Google Analytics does not imply user tracking beyond the landing page. Defenders should block 104.16.140.114 and any resolution to polkadot.fi at the network perimeter and within endpoint controls. Adding the domain to local blacklists and ensuring the four blocklist providers are incorporated into detection pipelines will reduce exposure. Continuous monitoring of the registration record and periodic re‑scans with VirusTotal are recommended to capture any changes in the threat posture.
Розвіддані з мережевої безпеки
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Технології · 2 identified
Google Analytics is a free web analytics service that tracks and reports website traffic.
google.com 100% впевненостіHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100% впевненостіАналіз VirusTotal
Архівні докази
Аналіз конфігурації сайту
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога