emberlord[.]top
“Emberlord: Most Popular Online Crypto Casino Based on Blockchain”
证据摘要
The domain emberlord.top was registered on 21 February 2026 and is currently taken offline. Analysis of public intelligence shows the site presented the page title “Emberlord: Most Popular Online Crypto Casino Based on Blockchain”, indicating a crypto‑casino lure. The site employed the publicly identified “Gambler Scam” phishing kit, a package commonly used to harvest credentials for cryptocurrency services. Scanning on VirusTotal recorded 13 detections out of 95 security vendors, confirming that multiple AV engines classify the host as malicious.
The SSL certificate is listed as “WE1”, which provides no assurance of legitimacy, and the Gridinsoft trust score is 0 out of 100, the lowest possible rating. Network resolution points to IP address 172.67.178.49, which belongs to AS13335 Cloudflare, Inc. and is geolocated in the United States; the same IP is frequently shared by other malicious actors due to Cloudflare’s reverse‑proxy model. The domain appears on one known security blocklist and has been explicitly blocked by the PhishDestroy feed, reinforcing its classification as a threat. The combination of a recent registration, use of a known scam kit, low trust metrics, multiple vendor detections, and inclusion on blocklists suggests a high likelihood that the site was used to deceive victims into entering crypto‑related credentials or payments.
Because the site is offline, direct forensic capture of page content is not possible, leaving the exact content and any additional payloads unverified. Defenders should continue to block the domain at DNS and proxy layers, monitor for any future re‑registration of the same name, and add the associated IP address to threat‑intel feeds. Additional scrutiny of traffic to Cloudflare‑hosted IP ranges that match the observed address is advised, as attackers may shift to other domains using the same infrastructure.
Data Coverage
威胁响应 Pipeline
阻止列表覆盖
监控中的外部数据源 10 个 · 已存快照 2026年8月12日
取证情报
VirusTotal 分析
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。
检查任意域名
使用存储的阻止列表、WHOIS、DNS 和公共扫描证据进行威胁分析
立即扫描举报网络钓鱼
将可疑域名提交至我们的威胁数据库——保护社区
报告实时威胁动态
最近的网络钓鱼报告和观察到的可用性变化
监控