MALICIOUS — HIGH
compound-crypto[.]net
2 of 93 security engines flagged the domain; the latest stored check returned HTTP 502.
- VirusTotal
- 2/93
- Blocklists
- No stored match
- 可用性
- 内容不可用 · HTTP 502
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
compound-crypto.net — 内容不可用 (HTTP 502). 品牌冒充:Compound; 诈骗类型:Crypto Scam. 证据摘要: VirusTotal 2/93 (Seclookup, SOCRadar); PhishDestroy score 63/100. 注册商: Web Commerce Communica….
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
Evidence Digest
compound-crypto.net is classified high with an evidence score of 63/100. 2 of 93 security engines flagged the domain. Registered 21 Feb 2026 via Web Commerce Communications Limited, hosted on 193.24.123.182 (PROSPERO-AS PROSPERO OOO, RU, RU). The latest stored check on 9 Aug 2026 returned HTTP 502 and includes a capture.
Stored generated summary (templated)cerebras · 2026年7月25日
Retained for the record. This text repeats stored detection facts and is not presented as authored analysis.
The domain compound-crypto.net was registered on 21 February 2026 through Web Commerce Communications Limited. DNS resolution points to the IPv4 address 193.24.123.182, which belongs to ASN 200593 (PROSPERO OOO) and is geolocated in Russia. The domain is served behind Cloudflare, as indicated by the authoritative nameservers dora.ns.cloudflare.com and vick.ns.cloudflare.com and the presence of Cloudflare Browser Insights and HTTP/3 in the traffic fingerprint. The TLS certificate presented is issued by Google Trust Services under the WE1 intermediate, confirming the use of a legitimate certificate chain. Public threat‑intelligence sources have classified the site as a “Crypto Scam” that impersonates the DeFi platform Compound.
The page title returned by the server is “404 Not Found”, and the current operational status is listed as offline. The domain appears on a single security blocklist and has been blocked by the PhishDestroy feed. VirusTotal analysis shows that 2 of 93 scanning engines have flagged the domain as malicious, providing additional corroboration of its suspicious nature. While the SSL certificate is valid, the combination of a Russian‑hosted IP, Cloudflare front‑end, and the explicit brand‑impersonation claim aligns with typical infrastructure used by financially motivated actors targeting cryptocurrency users. No Safe Browsing or Open Threat Exchange entries were observed for this domain, and no public evidence links have been published.
Consequently, the confidence in the malicious classification is elevated but not absolute, because the site is presently offline and limited external observations exist. Defenders should add compound-crypto.net to block lists, enforce DNS‑level denial for client resolvers, and monitor the associated IP range (193.24.123.0/24) for any re‑activation. Continuous re‑scanning with multi‑engine services such as VirusTotal is advised to capture any changes in the detection profile.
数据覆盖范围12 recorded checks
威胁响应 Pipeline
公共封禁名单状态
已保存的截图
域名情报
技术细节DNS、SSL SAN、时间戳
ICANN OVERSIGHT
认证和 RAA 背景
认证和 RAA 背景
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
所用技术 · 3 identified
Performance monitoring tool that measures website speed from real users.
www.cloudflare.comWeb infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
VirusTotal 分析
证据与外部报告Independent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。