MALICIOUS — CRITICAL
purchase2-blockdag[.]pages[.]dev
PhishDestroy identifies purchase2-blockdag.pages.dev as an active banking phishing domain luring users with BlockDAG branding.
- VirusTotal
- 14/91
- Blocklists
- 2 · ScamSniffer, Enkrypt
- Доступність
- Останній відомий активний · HTTP 200
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
purchase2-blockdag.pages.dev — Останній відомий активний (HTTP 200). Зведення доказів: VirusTotal 14/91 (alphaMountain.ai, BitDefender, CyRadar, ESET, Emsisoft); URLQuery 2 alerts; Google Safe Browsing flagged; 2 external blocklist matches (ScamSniffer, Enkrypt); PhishDestroy score 100/100. Реєстратор: Cloudflare.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
Evidence Analysis
PhishDestroy identifies purchase2-blockdag.pages.dev as an active banking phishing domain luring users with BlockDAG branding. The page masquerades as a legitimate purchase portal while deploying a drainer kit to harvest cryptocurrency and sensitive credentials. This domain weaponizes social engineering tactics through a spoofed interface designed to mimic BlockDAG’s official ecosystem, tricking visitors into authorizing fraudulent transactions.
Technical indicators confirm high-risk compromise: VirusTotal analysis reveals a detection ratio of 14/95 security vendors, while Google Safe Browsing classifies the site under SOCIAL_ENGINEERING. The domain operates under Cloudflare’s registrar infrastructure, resolving to IP 172.66.44.167 via a Google Trust Services-issued SSL certificate. Security research confirms the domain has been flagged by at least two public blocklists and blocked by Enkrypt and ScamSniffer, highlighting its malicious reputation.
Current status shows the domain remains active and unresolved despite multiple detections, posing an ongoing threat to unprotected users. Immediate action is recommended: block network traffic to 172.66.44.167 and the domain itself, revoke any unauthorized crypto transaction approvals, and audit browser extensions for injected scripts. Remaining risk is high due to the drainer’s ability to bypass some endpoint defenses, emphasizing the need for layered security controls including DNS filtering and user awareness training.
Обсяг даних13 recorded checks
Розвіддані з мережевої безпеки
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Private YARA rules | purchase2-blockdag.pages.dev/9775c54e7ff594791459.js |
audit | Hunting_JS_WebAssembly |
| DNS4EU | purchase2-blockdag.pages.dev |
malicious | Sinkholed |
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Технології · 6 identified
HTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org 100% впевненостіGoogle Tag Manager is a tag management system (TMS) that allows you to quickly and easily update measurement codes and related code fragments collectively known as tags on your website or mobile app.
www.google.com 100% впевненостіGoogle Analytics is a free web analytics service that tracks and reports website traffic.
google.com 100% впевненостіFacebook pixel is an analytics tool that allows you to measure the effectiveness of your advertising.
facebook.com 100% впевненостіCloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com 100% впевненостіHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100% впевненостіАналіз VirusTotal
Архівні докази
Докази та зовнішні звітиIndependent lookups and source reports
“Angel drainer”
Victim safety and official reportingImmediate actions and verified reporting channels
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.