VirusTotal
4 / 92
“Home - Web3 connects - A crypto buy and sell marketplace”
web3cryptosecure.online — Контент недоступний. Тип шахрайства: Generic Phishing. Зведення доказів: VirusTotal 4/92 (ADMINUSLabs, alphaMountain.ai, Fortinet, Gridinsoft); URLQuery 1 alert; Spamhaus DBL_PHISH; 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 95/100. Реєстратор: Porkbun.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
4 / 92
1 threat-system alert
ПовідомитиDBL_PHISH
checked — no match recorded
no community references
Повідомитиprovider verdict: clean
Повідомитизбережений звіт
Повідомити 14 перевірено — блокувань немає
44/100
ПовідомитиChecked; no threat flag recorded
Повідомити| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DNS4EU | web3cryptosecure.online |
malicious | Sinkholed |
This domain, web3cryptosecure.online, has been flagged for active credential theft targeting cryptocurrency users. The site masquerades as a legitimate Web3 security portal, luring victims into entering private wallet keys or seed phrases under the guise of 'enhanced verification.' Once harvested, stolen credentials enable immediate crypto drainer attacks, where funds are transferred to attacker-controlled wallets within minutes. The domain leverages urgency-based messaging (e.g., 'Your wallet is at risk—verify now to secure assets') to bypass user skepticism, a hallmark of modern crypto credential theft operations.
Evidence confirms this domain is a high-risk threat vector. Registered through Porkbun LLC on January 20, 2026, the site hosts a Let's Encrypt SSL certificate to appear legitimate but has evaded detection with 4/95 VirusTotal scans as of latest checks. Its IP resolution (5.39.69.62) aligns with newly allocated infrastructure typical of short-lived phishing campaigns. While not yet blacklisted, proactive blocking via DNS filters or host files is critical to prevent access. The combination of a freshly minted domain, low detection rates, and cryptocurrency-focused impersonation underscores elevated risk for unsuspecting users.
If you or someone you know visited web3cryptosecure.online, take immediate action. Disconnect the device from the internet to prevent potential malware deployment or credential interception. Review all crypto wallet transaction histories for unauthorized activity, and revoke any exposed seed phrases or private keys via supported wallet applications. Report the domain to your antivirus provider, domain registrars (Porkbun LLC), and platforms like PhishDestroy or Chainabuse for takedown escalation. Enable multi-factor authentication on all crypto accounts and consider migrating funds to newly generated wallets with no prior exposure. Stay vigilant—crypto credential theft operations evolve rapidly, and even 'low-risk' domains can escalate to active exploitation within hours.
Збережені дані спостережень за взаємодією веб-сканера та браузера для цього хоста, а також перевірка відбитків у режимі реального часу для систем розподілу трафіку типу «Кейтаро».
Примітка щодо сканера: unavailable: raw=connection_error; http=0; via=http_proxy; error=SOCKSHTTPConnectionPool(host='web3cryptosecure.online', port=80): Max retries exceeded with url: / (Caused by NewConnect
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
ns1.devserverdns.comns2.devserverdns.comweb3cryptosecure.onlinepriority 0Location describes the IP network.
efca33b748a72636fbcbd13ebb6c28384b9d59696b26299b014d47dac03bf471jobsinclines.com.ngweb3assetsfinance.onlinewww.web3assetsfinance.online.jobsinclines.com.ngwww.web3cryptosecure.online.jobsinclines.com.ngSaved certificate metadata. Certificate dates without a timezone are shown as stored. Transport encryption does not establish that the site is trustworthy.
Google PageSpeed Insights — mobile performance audit of web3cryptosecure.online · checked May 15, 2026
12 recorded events. These records describe collected evidence, outgoing notifications and publication; they do not confirm a complete investigation or a takedown.
We scan suspicious URLs, inspect public results and send evidence through the appropriate abuse-reporting channels. The dated events above show what is recorded for this domain. The directory below explains the wider workflow.
Capture the rendered page, requests and visible infrastructure.
Compare the available engine results and retain the analysis timestamp.
Check whether Google currently lists the URL as unsafe.
Inspect a public scan and its recorded network and classification data.
Look for indicator references and related community intelligence.
Compare archived captures and preserve historical context.
Look for matching indicators and associated threat records.
Inspect certificate records and related hostnames.
Compare security resolver responses and record observed blocking.
Inspect the public DNS, TLS, HTTP and technology surface.
Security services used for scanning, reputation checks and reporting are listed below. A service being listed is not evidence that it received, accepted or acted on this particular domain. Recorded submissions appear in the notification history above.
Повідомив 1 учасник спільноти; уперше помічено 15.05.2026
PD-20260515-0A3465 Recipient: abuse@ovh.net Policy Violations: Illegal Activities: Active phishing operation targeting victims Fraud & Deception: Impersonation of legitimate services Identity Theft: Collection of credentials under false pretenses Applicable Laws (Unknown): International Anti-Cybercrime Regulations Budapest Convention on Cybercrime Universal Fraud Prevention Laws Phishing activities violate international cybercrime conventions and Unknown's domestic fraud laws. Action Required: This evidence-backed report demonstrates clear violations requiring suspension per your policies. Continued hosting exposes your organization to regulatory scrutiny and potential legal liability.
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Template-based draft · optional AI wording assistance requires separate consent
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразДодавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиОстанні звіти про фішинг і помічені зміни доступності
ВідстежуватиСлідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога