toucan-delegator[.]cabana[.]fi
“Delegate - PoolTogether”
toucan-delegator.cabana.fi — Контент недоступний (HTTP 502). Уособлення бренду: ["optimism"]; Тип шахрайства: Crypto Drainer. Зведення доказів: VirusTotal 6/94 (alphaMountain.ai, CRDF, CyRadar, ESET, Gridinsoft); PhishDestroy score 68/100. Реєстратор: Gandi SAS.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
This domain, toucan-delegator.cabana.fi, presents a targeted credential theft threat specifically designed to impersonate PoolTogether’s delegation interface. Analysis indicates the site was engineered to harvest cryptocurrency wallet credentials and private keys under the guise of a legitimate delegation portal. The fraudulent page mimics PoolTogether’s branding, including an identical page title, 'Delegate - PoolTogether,' to deceive users into entering sensitive authentication details, which would then be exfiltrated to attacker-controlled infrastructure. Infrastructure analysis reveals the domain was registered through Gandi SAS on March 27, 2026, an anomalous future date suggesting potential domain spoofing or registry manipulation. The domain resolved to the IP address 76.76.21.123 and was flagged by 6 out of 95 security vendors on VirusTotal, indicating moderate detection coverage. Additionally, the domain appeared on one security blocklist prior to being taken offline, further corroborating its malicious intent. The Gridinsoft trust score of 0/100 underscores the domain’s complete lack of legitimacy. Users who visited toucan-delegator.cabana.fi should immediately revoke any active sessions or delegations associated with the fraudulent site. All credentials, private keys, or recovery phrases entered on the page must be considered compromised and should be rotated across all platforms where they were reused. Monitor connected wallets for unauthorized transactions and review recent delegation activities for anomalies. If financial loss occurred, report the incident to relevant blockchain analytics platforms and local cybercrime authorities with the domain, IP address 76.76.21.123, and seed identifier c0e610 for further investigation.
Розвіддані з мережевої безпеки
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Аналіз VirusTotal
Аналіз продуктивності сайту
Google PageSpeed Insights — mobile performance audit of toucan-delegator.cabana.fi · checked Jun 26, 2026
Докази та зовнішні звіти
PD-20260328-270DB6 Recipient: abuse@vercel.com Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога