cab[.]alveonltd[.]com
证据摘要
PhishDestroy identifies cab.alveonltd.com as an active crypto drainer impersonating Alveon Ltd, a legitimate entity in the digital asset space. This malicious domain leverages deceptive branding to trick users into connecting their wallets or entering credentials, risking irreversible cryptocurrency losses. The threat actors behind this campaign use social engineering tactics—such as fake giveaways or fraudulent investment opportunities—to lure victims to the site. Once accessed, the domain executes JavaScript-based wallet drainers or phishing forms to siphon funds directly from connected wallets or trick users into revealing private keys or seed phrases. Given its active status and lack of current detections, the risk of compromise remains high for unsuspecting visitors. This domain was flagged through PhishDestroy’s threat intelligence pipeline after analysis of its infrastructure and behavior. The domain resolves to IP 188.114.96.3 and operates under a Let’s Encrypt SSL certificate, which may lend it an air of legitimacy. Notably, it shows 0 detections on VirusTotal out of 95 engines scanned, indicating a low signature-based detection rate. The domain was registered on March 3, 2026, through TUCOWS.COM, CO., a registrar that has historically been used in both legitimate and malicious deployments. While no active blocklist entries have been identified yet, its recent creation and clean reputation suggest it is a newly deployed threat designed to evade early detection. Users who have visited cab.alveonltd.com should immediately disconnect any connected wallets from the site, revoke any unintended token approvals via blockchain explorers like Etherscan or BscScan, and scan their devices for malware. Do not interact with any prompts or forms on the domain, and avoid re-visiting the link. Report this domain to PhishDestroy and your organization’s SOC for further analysis. If you entered credentials or wallet information, assume compromise and transfer remaining assets to a new, secure wallet. Always verify links and domains—especially those mimicking brands—using PhishDestroy’s real-time verification tools before taking any action.
已提交证据快照
- 已发送
- 台账记录
- 1
- 案件 ID
PD-20260408-15BEAF- 已捕获页面标题
- Alveon
- PDF 文件
- PDF 证据
法律依据
完整证据文本
Illegal Activities: Active phishing operation targeting victims
Fraud & Deception: Impersonation of legitimate services
Identity Theft: Collection of credentials under false pretenses
Applicable Laws (KN):
International Anti-Cybercrime Regulations
Budapest Convention on Cybercrime
Universal Fraud Prevention Laws
Phishing activities violate international cybercrime conventions and KN's domestic fraud laws.
Action Required: This evidence-backed report demonstrates clear violations requiring suspension per your policies. Continued hosting exposes your organization to regulatory scrutiny and potential legal liability.
Data Coverage
威胁响应 Pipeline
阻止列表覆盖
监控中的外部数据源 10 个 · 已存快照 2026年8月12日
已保存的截图
域名情报
技术详情DNS、TLS 名称和时间戳
ICANN OVERSIGHT
Registration: alveonltd.com
认证和 RAA 背景
认证和 RAA 背景
Registrar accreditation and DNS abuse obligations
For the registrable domain alveonltd.com behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
VirusTotal 分析
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。
检查任意域名
使用存储的阻止列表、WHOIS、DNS 和公共扫描证据进行威胁分析
立即扫描举报网络钓鱼
将可疑域名提交至我们的威胁数据库——保护社区
报告实时威胁动态
最近的网络钓鱼报告和观察到的可用性变化
监控