holo[.]nvault[.]live
“holo | Airdrop”
证据摘要
The domain holo.nvault.live was a phishing site engaged in brand impersonation, specifically targeting Twitter users with a cryptocurrency scam. It presented itself as a legitimate Twitter-related airdrop page under the title 'holo | Airdrop' but had no association with the official platform. No drainer kit was identified, and the site is currently taken offline, reducing immediate risk to users.
Technical analysis of holo.nvault.live revealed limited detection, with 1 of 95 VirusTotal security vendors flagging it, including Gridinsoft, which assigned a trust score of 0/100. The domain appeared on 1 security blocklist, PhishDestroy, while Google Safe Browsing did not flag it. Created on February 21, 2026, the domain resolved to the IP address 104.21.32.195, hosted by Cloudflare in the US (AS13335). The SSL certificate was issued by WE1, a common provider for low-reputation domains.
Users who interacted with holo.nvault.live should take immediate steps to secure their accounts and assets. For cryptocurrency-related scams, revoke any token approvals granted to unknown contracts and transfer funds to a new wallet. If login credentials were entered, change passwords for the affected accounts, enable two-factor authentication, and monitor for unauthorized activity. Report the domain to platforms like Google Safe Browsing, PhishTank, or the impersonated brand’s security team to aid in takedown efforts.
Data Coverage
威胁响应 Pipeline
阻止列表覆盖
监控中的外部数据源 10 个 · 已存快照 2026年8月12日
取证情报
VirusTotal 分析
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。
检查任意域名
使用存储的阻止列表、WHOIS、DNS 和公共扫描证据进行威胁分析
立即扫描举报网络钓鱼
将可疑域名提交至我们的威胁数据库——保护社区
报告实时威胁动态
最近的网络钓鱼报告和观察到的可用性变化
监控