ftp[.]coingecko[.]pl
“Tani i szybki hosting WWW. Tanie domeny z hostingiem w SeoHost.pl”
证据摘要
The domain ftp.coingecko.pl is flagged as a high-risk phishing site currently active. Registered on July 04, 2025, through Aftermarket.pl Limited, the domain resolves to IP address 188.210.221.51, hosted in Poland on AS50599 (DATASPACE P.S.A.). The domain uses nameservers ns1.seohost.pl and ns2.seohost.pl, and its page title is 'Tani i szybki hosting WWW. Tanie domeny z hostingiem w SeoHost.pl', indicating a generic hosting service facade. The site is impersonating a target identified as 'across' in the intelligence, with the scam type classified as cryptocurrency. Despite the hosting-oriented title, the domain's association with cryptocurrency scams and its low trust score (0/100 by Gridinsoft) suggest it is likely part of a broader phishing campaign targeting users in the crypto space. The domain is detected by 1 security blocklist and flagged by 1 out of 95 security vendors on VirusTotal, indicating limited but confirmed detection. An SSL certificate issued by Let's Encrypt (R13) is present, which provides basic encryption but does not verify legitimacy. The site returns HTTP status 200, confirming it is operational and accessible. Uncertainties remain regarding the exact phishing mechanism, as the page content has not been directly analyzed. The brand target 'across' is ambiguous; it may refer to a specific cryptocurrency platform or a generic cross-brand campaign, but without further evidence, the exact impersonated entity is not confirmed. The low VirusTotal detection rate could suggest the site is either newly active, using evasive techniques, or that it has not yet been widely reported. Defenders should treat this domain as actively hostile, block access at the network level, and monitor for related domains under the same registrar or hosting infrastructure. Users who may have interacted with the site should be warned to change credentials and avoid further engagement. Investigation into the ASN and hosting provider may assist in takedown efforts.
Data Coverage
威胁响应 Pipeline
阻止列表覆盖
监控中的外部数据源 10 个 · 已存快照 2026年8月12日
检测时间线
-
Cloudflare Radar
已存储 Cloudflare Radar 扫描 · 打开扫描
VirusTotal 分析
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。
检查任意域名
使用存储的阻止列表、WHOIS、DNS 和公共扫描证据进行威胁分析
立即扫描举报网络钓鱼
将可疑域名提交至我们的威胁数据库——保护社区
报告实时威胁动态
最近的网络钓鱼报告和观察到的可用性变化
监控