whatifxchange[.]rewardsinwhatif[.]app
“WHATIFX DEX Aggregator”
whatifxchange.rewardsinwhatif.app — Неперевірений. Тип шахрайства: Fake Airdrop. Зведення доказів: VirusTotal 11/91 (ADMINUSLabs, BitDefender, Chong Lua Dao, CRDF, CyRadar); PhishDestroy score 83/100. Реєстратор: GoDaddy.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
PhishDestroy identifies whatifxchange.rewardsinwhatif.app as a live crypto drainer impersonating the WHATIFX DEX Aggregator platform. This domain uses deceptive branding to trick cryptocurrency traders into connecting their wallets, ultimately siphoning digital assets through malicious smart contract interactions. The site’s SSL certificate is issued by Google Trust Services, lending a false sense of legitimacy, but the underlying infrastructure at IP 199.36.158.100 has not yet been flagged by most antivirus engines, as evidenced by VirusTotal’s 8 out of 95 detections. The domain presents itself with the page title WHATIFX DEX Aggregator, directly mimicking a legitimate decentralized exchange aggregator. Registration data (not explicitly provided) combined with the recent appearance of the page suggests this is a newly created resource designed for short-lived malicious campaigns. The absence of blocklist detections indicates the campaign is still in early stages, exploiting the trust associated with WHATIFX branding to bypass user scrutiny. The IP address 199.36.158.100 is associated with broader hosting infrastructure that has been observed in prior crypto drainer operations, though no definitive attribution can be made based solely on current indicators. Users who visited whatifxchange.rewardsinwhatif.app should immediately revoke any wallet connections made through the site using tools like WalletConnect or MetaMask’s connection manager. Disconnect the domain and clear browser cache and local storage to remove any session artifacts. Monitor wallet activity for unauthorized transactions and report any suspicious withdrawals to your wallet provider or block explorer. Consider using a hardware wallet or dedicated browser profile with limited permissions for future DeFi interactions. Report the domain to your antivirus vendor, browser security teams, and domain registrars like Google Trust Services to aid in takedown efforts and prevent further victimization.
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Збережений знімок
Аналітика доменів
Технічні деталіDNS, SAN-адреси SSL, мітки часу
ICANN OVERSIGHT
Registration: rewardsinwhatif.app
Акредитація та контекст RAA
Акредитація та контекст RAA
Registrar accreditation and DNS abuse obligations
For the registrable domain rewardsinwhatif.app behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Аналіз VirusTotal
Аналіз продуктивності сайту
Google PageSpeed Insights — mobile performance audit of whatifxchange.rewardsinwhatif.app · checked Apr 7, 2026
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога