www-safepal[.]com
www-safepal.com — Неперевірений. Уособлення бренду: SafePal; Тип шахрайства: Crypto Scam. Зведення доказів: VirusTotal 18/91 (ADMINUSLabs, Criminal IP, alphaMountain.ai, Bfore.Ai PreCrime, BitDefender); URLQuery 2 alerts; Spamhaus DBL_PHISH; PhishDestroy score 100/100. Реєстратор: Web Commerce Communica….
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
Analysis indicates that the domain www-safepal.com was registered on 21 February 2026 through Web Commerce Communications Limited operating as WebNic.cc. The authoritative nameservers ns100.webnic.cc and ns101.webnic.cc resolve the domain to the IPv4 address 216.120.147.200, which is hosted by Bodis, LLC in the United States. The IP address appears on a single security blocklist and has been flagged by PhishDestroy as part of a crypto‑related brand‑impersonation campaign. VirusTotal scans show that 15 of 93 security vendors assign a malicious verdict to the domain, reflecting a moderate detection rate.
The Gridinsoft trust score of 20 out of 100 further confirms a low reputation. AlienVault OTX contains the domain in one threat‑intelligence pulse, providing additional corroboration of its malicious use. The domain is explicitly listed as impersonating the cryptocurrency wallet brand SafePal and is categorized as a crypto scam. As of the report date, the site is taken offline, but historical activity suggests it was used to lure victims into fraudulent cryptocurrency transactions.
Defenders should add www-safepal.com to deny‑list rules, block the associated IP 216.120.147.200 at network perimeters, and monitor for any residual traffic targeting the nameservers. Continuous retrieval of threat‑intel feeds, including PhishDestroy, OTX, and VirusTotal, is recommended to capture any re‑hosting attempts. Because no page‑title or content snapshot is available, further forensic analysis of any cached copies would be required to confirm the exact lure techniques employed.
Сигнали безпеки
Розвіддані з мережевої безпеки
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Hagezi Threat Feed | www-safepal.com |
malicious | Sinkholed |
| DNS4EU | www-safepal.com |
malicious | Sinkholed |
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Збережений знімок
Аналітика доменів
Технічні деталіDNS, SAN-адреси SSL, мітки часу
ICANN OVERSIGHT
Акредитація та контекст RAA
Акредитація та контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Аналіз VirusTotal
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога