sso-ndax-lginapp-cdn[.]webflow[.]io
“NDAX® | Login: Canada’s Most Secure Crypto Exchange”
sso-ndax-lginapp-cdn.webflow.io — Контент недоступний. Тип шахрайства: Fake Exchange. Зведення доказів: VirusTotal 16/91 (alphaMountain.ai, BitDefender, Chong Lua Dao, CyRadar, ESET); CF Radar malicious; PhishDestroy score 95/100. Реєстратор: Webflow.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
This domain is actively engaged in crypto credential theft, specifically targeting users of the legitimate NDAX cryptocurrency exchange platform. Analysis indicates the infrastructure is designed to harvest login credentials, potentially enabling unauthorized access to user accounts and subsequent theft of digital assets. The page title, 'NDAX® | Login: Canada’s Most Secure Crypto Exchange,' directly mirrors the branding of the authentic exchange, increasing the likelihood of successful deception among users seeking to access their accounts. Infrastructure analysis reveals multiple high-confidence threat indicators. The domain, registered through Webflow, resolves to the IP address 104.18.36.248 and is currently flagged by 15 out of 95 security vendors on VirusTotal. Additionally, the domain appears on one security blocklist, further corroborating its malicious intent. While the exact creation date of the domain is not publicly disclosed, the combination of brand impersonation, active status, and vendor detections strongly suggests a recently deployed phishing operation. Users who have visited this domain or entered credentials should take immediate action to mitigate potential risks. First, revoke any active sessions on the legitimate NDAX platform and reset account passwords using a secure, unrelated device. Enable multi-factor authentication if not already active, and monitor all linked accounts for unauthorized transactions or suspicious activity. If financial loss is suspected, report the incident to relevant authorities and the legitimate exchange to initiate fraud response protocols. Given the high-risk nature of this threat, affected users should also consider scanning their devices for malware or unauthorized access tools.
Розвіддані з мережевої безпеки
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Технології · 3 identified
Webflow is Software-as-a-Service (SaaS) for website building and hosting.
webflow.com 100% впевненостіCloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com 100% впевненостіHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100% впевненостіАналіз VirusTotal
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога