cryptocomnilogin[.]webflow[.]io
“Crypto.com Login | DeFi Desktop Wallet”
已存储的观测记录
观测到的标题差异
证据摘要
This domain, cryptocomnilogin.webflow.io, is flagged for brand impersonation targeting Crypto.com, a cryptocurrency exchange platform. Analysis indicates the site hosted a fake login portal titled 'Crypto.com Login | DeFi Desktop Wallet,' designed to harvest user credentials or facilitate unauthorized access to digital wallets. No direct evidence of a cryptocurrency drainer kit was identified, but the page structure aligns with credential theft tactics commonly employed in phishing campaigns targeting financial services. Infrastructure analysis reveals the domain was registered through Webflow and resolves to the IPv6 address 2a06:98c1:3100::6812:24f8, hosted on Cloudflare's network (AS13335). The domain was created on March 12, 2026, though this date may reflect a placeholder or misconfiguration. VirusTotal detection metrics show 18 out of 95 security vendors flagged the domain as malicious. The domain appears on one security blocklist and was previously blocked by internal detection systems. SSL certificate analysis indicates a Cloudflare-issued WE1 certificate, consistent with standard hosting configurations but offering no inherent trust indicators. The domain is currently offline, mitigating immediate risk to end users. However, historical exposure remains a concern, as credentials or sensitive data submitted prior to takedown may still be exploited. Organizations should monitor for unauthorized access attempts linked to this domain and implement additional authentication controls for users who may have interacted with the site. Continuous scanning for domain squatting variants (e.g., typosquatting, homoglyphs) targeting Crypto.com is recommended to preempt similar threats. No residual infrastructure risks were identified post-takedown, but threat actors may attempt to re-establish the campaign under a new domain.
Data Coverage
网络安全情报
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Cloudflare DNS | cryptocomnilogin.webflow.io |
malicious | Sinkholed |
| OpenDNS | cryptocomnilogin.webflow.io |
phishing | Phishing Block |
| DNS4EU | cryptocomnilogin.webflow.io |
malicious | Sinkholed |
威胁响应 Pipeline
阻止列表覆盖
监控中的外部数据源 10 个 · 已存快照 2026年8月10日
检测时间线
-
Cloudflare Radar
已存储 Cloudflare Radar 扫描 · 打开扫描
技术
识别出 3 项高置信度技术
VirusTotal 分析
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。
检查任意域名
使用存储的阻止列表、WHOIS、DNS 和公共扫描证据进行威胁分析
立即扫描举报网络钓鱼
将可疑域名提交至我们的威胁数据库——保护社区
报告实时威胁动态
最近的网络钓鱼报告和观察到的可用性变化
监控