ffloat[.]net
ffloat.net 网络钓鱼与安全检查
“FFloat Guide | ÐонвеÑÑаÑÐ¸Ñ ÐºÑипÑовалÑÑ Ð² Ñиає
ffloat.net — 内容不可用 (HTTP 502). 诈骗类型:Crypto Drainer. 证据摘要: VirusTotal 1/94 (Gridinsoft); PhishDestroy score 56/100. 注册商: NiceNIC.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
Domain ffloat.net has been flagged for hosting a generic crypto-drainer phishing kit masquerading as a 'FFloat Guide' conversion service. The page title and content are entirely in Russian, indicating a target audience likely interested in cryptocurrency conversion or arbitrage. No specific brand is impersonated beyond the generic term 'FFloat,' suggesting the operators are leveraging a newly minted term to avoid immediate detection. The kit’s purpose is to trick visitors into connecting crypto wallets and signing malicious transactions that drain balances. The domain was registered through NICENIC INTERNATIONAL GROUP CO., LIMITED on April 17, 2026, and is currently resolving to IP 188.114.97.3 via a Let's Encrypt SSL certificate. The domain remains unflagged on VirusTotal with 1/95 detections as of this report. No known blocklist entries or Google Safe Browsing (GSB) flags have been recorded to date, indicating low prior visibility in threat intelligence feeds.
PhishDestroy identifies ffloat.net as a high-risk crypto-drainer operation based on multiple technical indicators. The domain was created on April 17, 2026, and is registered under NICENIC INTERNATIONAL GROUP CO., LIMITED. It resolves to IP address 188.114.97.3 and uses a valid SSL certificate issued by Let's Encrypt. The site currently shows zero detections on VirusTotal (1/95 engines), and no presence in public blocklists or GSB denylists has been detected. The page content—titled 'FFloat Guide | Конвертация криптовалюты в фиат'—suggests a Russian-language lure targeting users seeking crypto-to-fiat conversion tools. The absence of prior detection flags and the new domain registration strongly indicate a recently deployed, likely automated phishing campaign with minimal footprint in threat intelligence platforms.
As of this report, ffloat.net remains active and is actively serving the crypto-drainer payload. No takedown or remediation has been observed, and the domain continues to resolve normally. Given the zero VirusTotal detection rate and lack of blocklist presence, the risk to users remains elevated and unmitigated. PhishDestroy advises users to avoid visiting ffloat.net and to verify any similar sites using our platform before interacting. The current threat level is classified as 'under_investigation' pending further intelligence updates. Users who may have already visited the site are urged to revoke any wallet connections made via browser extensions or dApps, and to monitor their transaction histories for unauthorized transfers.
网络安全情报 Registrar context
威胁响应 Pipeline
公共封禁名单状态
已保存的截图
域名情报
技术细节DNS、SSL SAN、时间戳
ICANN OVERSIGHT
认证和 RAA 背景
认证和 RAA 背景
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Latest Classified Outcome 2026-08-08 03:54:44 UTC
所用技术 · 4 identified
Cloudflare Browser Insights is a tool that measures the performance of websites from the perspective of users.
www.cloudflare.com 置信度 100%Cloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com 置信度 100%HTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 置信度 100%VirusTotal 分析
网站性能分析
Google PageSpeed Insights — mobile performance audit of ffloat.net · checked Apr 23, 2026
证据与外部报告
PD-20260423-129637 Recipient: abuse@nicenic.net 您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。