hebys-nft[.]io
“Hebys”
证据摘要
This domain, hebys-nft.io, is an active crypto drainer scam targeting NFT users. Registered on September 5, 2025, through Dynadot LLC, it currently resolves to 104.21.21.198, a Cloudflare IP (AS13335) located in the US. The site returns an HTTP 403 status, indicating access restrictions, but remains operational behind Cloudflare’s infrastructure, which also provides its SSL certificate (Google Trust Services / WE1). Nameservers demi.ns.cloudflare.com and ned.ns.cloudflare.com further confirm Cloudflare’s role in hosting this threat. Analysis indicates detection by 11 of 95 security vendors on VirusTotal, though the specific engines flagging it are not detailed.
The domain appears on one security blocklist and is referenced in a single AlienVault OTX pulse, suggesting limited but confirmed malicious activity. Gridinsoft assigns it a trust score of 0/100, and PhishDestroy blocks it, reinforcing its classification as high-risk. The page title 'Hebys' aligns with the domain’s branding, though no further content analysis is available. Technologies detected include Vue.js, HSTS, and HTTP/3, which may be used to enhance the site’s functionality or evade detection.
The use of Cloudflare complicates takedown efforts and obscures the true origin of the infrastructure. Defenders should treat this domain as active and malicious, blocking it at the network level and monitoring for related indicators. Given its crypto drainer classification, users interacting with this site risk unauthorized asset transfers. No evidence suggests a broader campaign, but the domain’s persistence and Cloudflare hosting warrant continued scrutiny.
Data Coverage
威胁响应 Pipeline
阻止列表覆盖
监控中的外部数据源 10 个 · 已存快照 2026年8月12日
VirusTotal 分析
网站性能分析
Google PageSpeed Insights — mobile performance audit of hebys-nft.io · checked Mar 2, 2026
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。
检查任意域名
使用存储的阻止列表、WHOIS、DNS 和公共扫描证据进行威胁分析
立即扫描举报网络钓鱼
将可疑域名提交至我们的威胁数据库——保护社区
报告实时威胁动态
最近的网络钓鱼报告和观察到的可用性变化
监控