app-jitonetwork[.]xyz
“Jito MEV Harvesting | Harvest Liquid Staked SOL - Maximise your Revenue”
app-jitonetwork.xyz — 内容不可用. 品牌冒充:Jito; 诈骗类型:Investment Scam. 证据摘要: VirusTotal 15/92 (ADMINUSLabs, alphaMountain.ai, BitDefender, CRDF, CyRadar); URLQuery 1 alert; Google Safe Browsing flagged; 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 95/100. 注册商: PDR.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
This domain, app-jitonetwork.xyz, poses a high-risk brand impersonation threat targeting users of the Jito protocol, a platform for maximum extractable value (MEV) harvesting on the Solana blockchain. The site mimics legitimate Jito interfaces by displaying the page title 'Jito MEV Harvesting | Harvest Liquid Staked SOL - Maximise your Revenue,' designed to deceive users into entering sensitive credentials or connecting cryptocurrency wallets. The objective is to steal private keys, seed phrases, or directly siphon digital assets under the guise of offering enhanced MEV revenue opportunities. The domain specifically exploits trust in the Jito brand, which is associated with liquid staking and MEV strategies, making it a credible lure for cryptocurrency investors seeking yield optimization. Analysis indicates this domain was registered on May 13, 2024, through PDR Ltd. d/b/a PublicDomainRegistry.com, a registrar frequently observed in malicious infrastructure deployments. The domain resolves to the IP address 188.114.97.3, which has been associated with other high-risk activities. Detection metrics reveal significant concern among security vendors: 15 out of 95 engines on VirusTotal flag the domain as malicious, while Google Safe Browsing classifies it under 'SOCIAL_ENGINEERING.' Additionally, the domain appears on four independent security blocklists and is referenced in one AlienVault OTX threat intelligence pulse. These indicators confirm the domain’s role in a coordinated phishing campaign targeting cryptocurrency users. Users who visited app-jitonetwork.xyz should immediately revoke any wallet connections made to the site and cease all interaction. If credentials or private keys were entered, affected parties must transfer assets to a new, secure wallet and monitor all linked accounts for unauthorized transactions. It is recommended to scan local devices for malware, as phishing sites may deploy additional payloads. Cryptocurrency users should verify domain authenticity by cross-referencing official project communications and using trusted blocklists before engaging with any platform claiming to offer MEV or staking services. Immediate reporting to relevant security teams and financial platforms is advised to mitigate further risk exposure.
网络安全情报
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DNS4EU | app-jitonetwork.xyz |
malicious | Sinkholed |
威胁响应 Pipeline
公共封禁名单状态
已保存的截图
域名情报
技术细节DNS、SSL SAN、时间戳
ICANN OVERSIGHT
认证和 RAA 背景
认证和 RAA 背景
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
VirusTotal 分析
证据与外部报告
PD-20260513-EC86C1 Recipient: abuse@publicdomainregistry.com 您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。