Перейти до звіту про безпеку
⚠️
Цей домен було позначено як шкідливий
Системи безпеки повідомляють про виявлення: 1. Публічні списки блокувань, які повідомляють про збіг: 2. Будьте дуже обережні — не вводьте облікові дані чи особисту інформацію.
Безпека домену та аналіз загроз

shlb-io[.]com

Перевірка домену shlb-io.com на фішинг і безпеку

“SOU Dashboard | Shib.io”

Загрозливий вердикт Високий 66/100 оцінка доказів
Доступність Прикритий · доступний Доступність спостерігається за допомогою перевірок маскування
Сигнали ризику
Виявлення VirusTotal: 1/92 Spamhaus DBL: DBL_SPAM Збережений список блокувань відповідає: 2 Уособлення бренду: Shib Останній відомий активний
1/92 VT 09.05.2026 Недоступний з 06.06.2026 2 Blocklists Shib Фішинг з використанням облікових даних 1 Report Sent Cloaking AE AE
Огляд звіту

shlb-io.com — Прикритий · доступний (HTTP 404). Уособлення бренду: Shib; Тип шахрайства: Credential Phishing. Зведення доказів: VirusTotal 1/92 (Fortinet); Spamhaus DBL_SPAM; 2 external blocklist matches (MetaMask, SEAL); cloaking observed; PhishDestroy score 66/100. Реєстратор: Fewmoretaps OU d/b/a T….

Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.

Evidence Analysis

Stored analysis · 07.07.2026 Ref 539A4507

This domain, shlb-io.com, is identified as a high-risk phishing resource specializing in cryptocurrency brand impersonation. Analysis confirms the domain mimics the Shiba Inu (SHIB) ecosystem, presenting a fraudulent dashboard interface titled 'SOU Dashboard | Shib.io' designed to deceive users into disclosing wallet credentials or authorizing malicious transactions. The campaign aligns with known cryptocurrency drainer kit patterns, where victims are lured through social engineering tactics such as fake airdrops, token claims, or governance proposals. No explicit drainer kit fingerprint was recovered from the offline page, though the structure and page title strongly suggest intent to harvest sensitive blockchain interaction data.

Technical indicators reveal multiple red flags associated with this domain. According to aggregated threat intelligence, shlb-io.com is flagged by 14 out of 95 security vendors on a major scanning platform, indicating broad consensus on its malicious nature. The domain was registered on May 9, 2026, through Fewmoretaps OU operating under the alias Trustname.com, a registrar frequently observed in high-risk domain registrations. Infrastructure analysis shows the domain resolved to the IP address 31.59.39.218, a host with no prior legitimate association with the targeted brand. The domain appears on three independent security blocklists and is actively blocked by multiple browser-based and wallet-level protection mechanisms. No detection was reported by Google Safe Browsing at the time of analysis, though this may reflect latency in feed updates rather than benign status.

As of the latest verification, shlb-io.com has been taken offline, likely in response to detection and reporting by security researchers and automated monitoring systems. While the immediate threat vector is neutralized, the domain registration remains active, posing a residual risk of reactivation under altered infrastructure. Users who interacted with the site prior to takedown are advised to revoke any suspicious smart contract approvals, rotate credentials associated with cryptocurrency wallets, and monitor connected accounts for unauthorized transactions. Organizations managing cryptocurrency-related security are encouraged to update internal blocklists with the domain, IP, and registrar details to prevent future exposure. Continued vigilance is warranted, as threat actors frequently re-deploy similar infrastructure under new domains following disruption.

VirusTotal
VirusTotal
1 det.
URLScan
URLScan
Сертифікат TLS
Прострочений або неперевірений
Вік
3 mo
Зафіксований статус
Прикритий · доступний 404
PhishDestroy
DestroyList
У списку
Reports Sent
1
Обсяг даних12 recorded checks
VirusTotal 1 / 92 URLQuery checked — no detections recorded PhishStats checked — no match recorded OTX no community references CF Radar scan completed URLScan capture збережений звіт URLScan verdict Аналіз завершено Блокування DNS 14 перевірено — блокувань немає TLS Прострочений або неперевірений WHOIS 3 mo old Знімок екрана 2 captures · 2 sources Ланцюжок перенаправлень не досліджено
Розвіддані з мережевої безпеки Registrar context
Registrar context Trustname
Stored registration data identifies Trustname / Fewmoretaps OÜ (IANA 4318) as the registrar. PhishDestroy maintains a separate registrar investigation; that material is contextual and is not an independent detection for this domain.
Trustname Investigation
SSL Certificate Invalid
SSL certificate is invalid or expired. Issuer:

Процес реагування на загрози Pipeline

Відкриття
Checks
Reports
Доступність
14/15
Sent Report Recorded
Stored sent-report record for registrar Fewmoretaps OU d/b/a Trustname.com, hosting provider, 2 abuse contacts
abuse@trustname.comabuse@eternitycloud.org
09.05.2026

Статус у публічних блоклистах

Збережений знімок

Заголовок сторінки
SOU Dashboard | Shib.io
Сертифікат TLS
Прострочений або неперевірений · Виданий Let's Encrypt / R12

Аналітика доменів

Домен
URLScan Verdict Аналіз завершено score 0 report ↗
Сервер / ASN nginx · AS212743 ETERNITY INTERNATIONAL LIMITED
Репутація IP abuse score 0/100 0 reports checked 13.07.2026
Реєстратор Fewmoretaps OU d/b/a T… BY(BY) PhishDestroy Investigation
IP-адреса 31.59.39.218 AE
ГеолокаціяAE Abu Dhabi, AE
МережаAS212743 · GoldIPv4
Зворотний пошук IPviewdns.info → rapiddns.io →
РеєстраціяСтворено 09.05.2026 (91d)
Статус HTTP404 Not Found
Cloaking Cloaking Detected Status split · score 1/6
dead_http: raw=http_404; http=404; via=https_proxy; server=nginx
server: nginx
checked 09.08.2026
Elapsed Since First Report 10h
Що ми враховуємо Raw elapsed time since the first stored abuse report. It is not a registrar response-time measurement. Latest observed status: Прикритий · доступний.
Що містить кожен звіт Збережені записи вихідних звітів можуть посилатися на докази, доступні на той час, наприклад вердикти постачальників, реєстраційні дані, деталі хостингу, класифікації або знімки екрана. Ця сторінка не визначає точного доставленого корисного навантаження, квитанції, підтвердження чи дії одержувача.
Технічні деталіDNS, SAN-адреси SSL, мітки часу
Вперше виявлено09.05.2026
IoC Extractionscanned 01.08.20260 wallet · 0 Telegram IoCs
Submitted URLhttp://shlb-io.com/
Сервери іменc.dnspod.com
TLS Fingerprint
TLS Observationvalid from 08.05.2026scanned 09.05.2026
TLS SAN Domainswww.shlb-io.com
Favicon Hash
Case ID
ICANN OVERSIGHT

Акредитація та контекст RAA

Registrar accreditation and DNS abuse obligations

For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.

Accreditation is a contract, not a safety certification.

RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.

Accountability draft Нічого не надсилається автоматично.
Технології · 1 identified
Nginx
Web servers Reverse proxies

Nginx is a web server that can also be used as a reverse proxy, load balancer, mail proxy and HTTP cache.

nginx.org 100% впевненості
Detected via Cloudflare Radar · Wappalyzer engine
Поскаржитися на цей домен Надішліть докази та допоможіть захистити інших

Аналіз VirusTotal

1 / 92 постачальників безпеки позначили цей домен
View on VT
Last analyzed
Fortinet
Аналіз продуктивності сайту

Google PageSpeed Insights — mobile performance audit of shlb-io.com · checked Jun 26, 2026

56
Needs Work
Performance
FCP
9.67s
First Contentful Paint
LCP
9.67s
Largest Contentful Paint
CLS
0
Cumulative Layout Shift
TBT
0ms
Total Blocking Time
SI
9.67s
Speed Index
Powered by Google PageSpeed Insights · Mobile strategy · Scores: 90-100 Good 50-89 Needs Work 0-49 Poor
Докази та зовнішні звітиIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
If credentials were compromised, report immediately. Do not engage with recovery scammers.

Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.

Європол
Знайдіть офіційний канал звітності для вашої країни ЄС
National police directory
Остерігайтеся шахраїв, які обіцяють повернути втрачені кошти! Злочинці можуть знову зв’язатися з жертвами, видаючи себе за слідчих, адвокатів або агентів із відновлення. Не сплачуйте авансових зборів і не діліться обліковими даними. Дізнайтеся більше про шахрайство у сфері відшкодування збитків →

Зверніться до місцевих органів влади

Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.

Довідник 97 країн
Чернетка за допомогою штучного інтелекту — деталі інциденту обробляються постачальником штучного інтелекту Перегляньте та подайте його самостійно
Вбудувати цей звітRead-only HTML widget
HTML · IFRAME

Вбудувати цей звіт

Поділіться цією інформацією про загрози на своєму веб-сайті або в блозі

embed.html
<iframe
  src="https://phishdestroy.io/uk/embed/domain/shlb-io.com"
  title="PhishDestroy threat report for shlb-io.com"
  width="100%" height="320"
  loading="lazy"
  referrerpolicy="no-referrer"
  sandbox="allow-same-origin allow-popups allow-popups-to-escape-sandbox"
  style="border:0;border-radius:12px;max-width:100%"
></iframe>

Дуже щирий лист-подяка

Генератор сатиричних чернеток

Одержувач
Контекст зборів

Це сатирична чернетка. Суми зборів є оцінками; ми не стверджуємо, що вони точно стосуються цього домену.