MALICIOUS — CRITICAL
egoexplore[.]ro
6 of 91 security engines flagged the domain; 2 public blocklists listed it (MetaMask, SEAL); the latest stored check returned HTTP 200.
- VirusTotal
- 6/91
- Blocklists
- 2 · MetaMask, SEAL
- 可用性
- 最后已知的活跃状态 · HTTP 200
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Notification and current-status evidence
The sent-report ledger records the first outgoing report at .
The recorded recipient is abuse@cyberfolks.ro.
The latest stored availability evidence still shows the domain reachable; 2 months has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
Jump to section
egoexplore.ro — 最后已知的活跃状态 (HTTP 200). 诈骗类型:Generic Phishing. 证据摘要: VirusTotal 6/91 (ChainPatrol, alphaMountain.ai, CRDF, Gridinsoft, SOCRadar); URLQuery 2 alerts; 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 85/100. 注册商: CYBER_FOLKS S.R.L.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
Evidence Digest
egoexplore.ro is classified critical with an evidence score of 85/100. 6 of 91 security engines flagged the domain; 2 public blocklists listed it (MetaMask, SEAL). Registered 29 Mar 2026 via CYBER_FOLKS S.R.L., hosted on 89.46.7.68 (Cyber_Folks SRL, RO). The latest stored check on 9 Aug 2026 returned HTTP 200 and includes a capture. 1 outgoing abuse report is recorded, most recently on 26 May 2026.
Stored generated summary (templated)mistral · 2026年6月26日
Retained for the record. This text repeats stored detection facts and is not presented as authored analysis.
This domain, egoexplore.ro, is a phishing site designed to steal cryptocurrency wallet credentials and private keys. Analysis indicates it mimics legitimate wallet interfaces to trick users into entering sensitive information, which attackers then use to drain digital assets from victims' accounts. The site specifically targets users of decentralized finance (DeFi) platforms and self-custody wallets, where recovery options are limited once funds are transferred. Infrastructure analysis reveals multiple red flags confirming its malicious nature. The domain was registered on March 29, 2026, through CYBER_FOLKS S.R.L., an unusual future date suggesting registry manipulation to evade detection. It resolves to IP address 89.46.7.68 and is hosted on a server running Nginx with OpenResty, a combination often used in phishing kits for its flexibility in handling malicious redirects. Security vendors have flagged it consistently: 5 out of 95 engines on VirusTotal detect it as malicious, and it appears on three independent blocklists. The SSL certificate issued by DigiCert Inc provides a false sense of security, as phishing sites commonly use valid certificates to appear legitimate. If you visited egoexplore.ro or entered any information on the site, immediate action is required to secure your assets. First, disconnect any connected wallets from the site using your wallet's interface and revoke all active permissions. Transfer remaining funds to a new wallet with a fresh seed phrase, as the existing one may be compromised. Monitor all connected accounts for unauthorized transactions and enable transaction alerts where possible. Report the incident to your wallet provider and consider filing a report with local cybercrime authorities. For future protection, verify domain registration dates and security vendor detections before interacting with any cryptocurrency-related site.
数据覆盖范围12 recorded checks
网络安全情报
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Hagezi Threat Feed | egoexplore.ro |
malicious | Sinkholed |
| Quad9 DNS | egoexplore.ro |
malicious | Sinkholed |
威胁响应 Pipeline
公共封禁名单状态
所用技术 · 2 identified
High-performance HTTP server and reverse proxy, known for stability and low resource usage.
Web platform based on Nginx with LuaJIT for scalable web apps.
VirusTotal 分析
网站性能分析
Google PageSpeed Insights — mobile performance audit of egoexplore.ro · checked Jun 26, 2026
证据与外部报告Independent lookups and source reports
PD-20260526-4A66DC Recipient: abuse@cyberfolks.ro Victim safety and official reportingImmediate actions and verified reporting channels
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。