user-monad[.]xyz
user-monad.xyz — Неперевірений. Уособлення бренду: Monad; Тип шахрайства: Brand Impersonation. Зведення доказів: VirusTotal 17/91 (ChainPatrol, alphaMountain.ai, BitDefender, Chong Lua Dao, CRDF); 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 95/100. Реєстратор: Dynadot.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
Analysis of the domain user-monad.xyz indicates an active brand impersonation campaign targeting Monad, a blockchain platform. The domain was registered on May 8, 2026, through Dynadot LLC and currently resolves to the IP address 188.114.96.3, hosted under CloudFlare, Inc. in Canada. Infrastructure analysis reveals CloudFlare nameservers (frida.ns.cloudflare.com and john.ns.cloudflare.com) and a Let's Encrypt SSL certificate (serial number E8), which are consistent with phishing domains leveraging content delivery networks to evade detection. The domain is flagged by three security blocklists and appears in one AlienVault OTX threat intelligence pulse, suggesting prior identification as malicious. Seven of 92 security vendors on VirusTotal classify this domain as malicious, though the exact nature of the threat—beyond brand impersonation—remains unconfirmed due to the HTTP 403 status, which restricts direct analysis of page content. The page title 'Just a moment...' is a common placeholder used by CloudFlare-protected sites, further obscuring the domain's operational state. Defenders should treat this domain as high-risk due to its active status, brand association, and detection by multiple security mechanisms, including MetaMask and SEAL. While the specific phishing kit or payload is not yet analyzed, the combination of registration recency, CloudFlare hosting, and brand impersonation aligns with tactics observed in cryptocurrency-related fraud. Network-level blocking of 188.114.96.3 and monitoring for related subdomains under user-monad.xyz are recommended until further analysis confirms or refutes the presence of malicious payloads.
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Аналітика доменів
Технічні деталіDNS, SAN-адреси SSL, мітки часу
ICANN OVERSIGHT
Акредитація та контекст RAA
Акредитація та контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Аналіз VirusTotal
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога