tokendistributions[.]cc
tokendistributions.cc — Неперевірений. Уособлення бренду: MetaMask; Тип шахрайства: Impersonation. Зведення доказів: VirusTotal 5/91 (alphaMountain.ai, CRDF, Forcepoint ThreatSeeker, Gridinsoft, SOCRadar); 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 95/100. Реєстратор: Global Domain Group.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
Analysis indicates that the domain tokendistributions.cc was registered on June 06, 2026 through the registrar Global Domain Group LLC. The domain currently resolves to the IPv4 address 188.114.96.3, an address that is part of a hosting range frequently observed in malicious campaigns and that does not resolve to any known corporate or content‑delivery network. VirusTotal data shows that five of ninety‑one scanning engines have flagged the domain as malicious, providing a modest but notable detection confidence. The domain appears on three independent security blocklists and is explicitly blocked by the PhishDestroy, MetaMask, and SEAL filtering services, all of which specialize in phishing and crypto‑related threats.
No SSL certificate details, HTTP status codes, or page‑title information have been published, so the exact payload or visual presentation of the site cannot be confirmed at this time. Likewise, there are no public entries in Safe Browsing or OTX for this domain, leaving the specific phishing kit, target brand, or lure technique undetermined. The combination of recent registration, a single‑purpose IP host, multiple vendor detections, and active blocklist listings leads to an elevated risk assessment for the domain.
Defensive recommendations include adding tokendistributions.cc to network‑level deny lists, configuring DNS sinkholing to intercept resolution attempts, monitoring outbound traffic to 188.114.96.3 for anomalous connections, and periodically re‑scanning the domain as additional telemetry becomes available. Continued vigilance is advised because the threat actor may activate additional infrastructure or modify the site content without notice.
Розвіддані з мережевої безпеки
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Аналітика доменів
Технічні деталіDNS, SAN-адреси SSL, мітки часу
Аналіз VirusTotal
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога