MALICIOUS — CRITICAL
qulotex[.]com
This domain, qulotex.com, was identified as part of a brand impersonation campaign targeting the cryptocurrency platform x.com.
- VirusTotal
- 9/93
- Blocklists
- No stored match
- sẵn có
- Nội dung không có sẵn · HTTP 502
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
qulotex.com — Nội dung không có sẵn (HTTP 502). Loại lừa đảo: Crypto Scam. Tóm tắt bằng chứng: VirusTotal 9/93 (alphaMountain.ai, BitDefender, CRDF, CyRadar, Fortinet); URLScan malicious verdict; PhishDestroy score 82/100. Nhà đăng ký: PDR.
Phân tích chi tiết của PhishDestroy AI bên dưới được giữ bằng tiếng Anh để bảo toàn hồ sơ pháp chứng gốc.
Evidence Analysis
This domain, qulotex.com, was identified as part of a brand impersonation campaign targeting the cryptocurrency platform x.com. The domain was registered through PDR Ltd. d/b/a PublicDomainRegistry.com on February 21, 2026. The site's page title, 'Qulotex: Most Popular Online Crypto Casino Based on Blockchain,' suggests it was designed to appear as a legitimate crypto casino, which is a common tactic in crypto scams to lure victims into providing sensitive information or making unauthorized transactions. The domain was flagged by 9 out of 93 security vendors on VirusTotal, indicating a significant level of suspicion among the cybersecurity community.
Additionally, it appears on one security blocklist, specifically PhishDestroy, which further corroborates the domain's involvement in phishing activities. The domain's current status is offline, and it resolves to the IP address 172.67.180.7, which is located in the United States and is associated with Cloudflare, Inc. (AS13335). The SSL certificate used was WE1, which may have been intended to add a false sense of security to unsuspecting users. Gridinsoft's trust score for this domain is 1 out of 100, reflecting a very low level of trust.
Defenders should be vigilant and ensure that any references to qulotex.com are blocked in their network security systems to prevent potential phishing attacks. The exact content of the site, including its specific impersonation techniques and layout, has not been analyzed, but the evidence strongly suggests that it was used as part of a Gambler Scam targeting cryptocurrency users. Regular monitoring and updating of security measures are recommended to mitigate the risk of similar phishing infrastructure.
Phạm vi dữ liệu13 recorded checks
Pipeline ứng phó với các mối đe dọa
Trạng thái trong danh sách chặn công khai
Bản chụp đã lưu
Thông tin về tên miền
Chi tiết kỹ thuậtDNS, SAN trong SSL, dấu thời gian
ICANN OVERSIGHT
Bối cảnh công nhận và RAA
Bối cảnh công nhận và RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Phân tích của VirusTotal
Bằng chứng và các báo cáo bên ngoàiIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
Nếu bạn đã nhập thông tin xác thực tài khoản, thông tin cá nhân hoặc thông tin thanh toán hoặc đã tải xuống tệp từ miền này, hãy hành động ngay lập tức. Dưới đây là các nguồn lực giúp bạn báo cáo vụ việc và bảo vệ chính mình.
Hãy báo cáo với chính quyền địa phương
Chọn quốc gia của bạn để nhận liên hệ tội phạm mạng chính thức hoặc soạn thảo đơn khiếu nại →.