investpvf[.]com
“Pvf Investment – Safe investment with Pvf Investment”
investpvf.com — 隐形 · 可达. 品牌冒充:Cryptoscam; 诈骗类型:Crypto Drainer. 证据摘要: VirusTotal 14/91 (ChainPatrol, alphaMountain.ai, BitDefender, CRDF, CyRadar); URLScan malicious verdict; Spamhaus DBL_SPAM; 2 external blocklist matches (MetaMask, SEAL); cloaking observed; PhishDestroy score 100/100. 注册商: Dynadot.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
PhishDestroy identifies investpvf.com as a live crypto drainer scam designed to trick users into connecting cryptocurrency wallets or entering seed phrases. This domain mimics legitimate investment platforms to steal digital assets, posing a severe risk to cryptocurrency holders seeking passive income opportunities. The threat actor leverages urgency and perceived legitimacy to deceive victims into authorizing malicious transactions or divulging sensitive wallet credentials.
This domain was flagged by security vendors with a VirusTotal detection ratio of 3 out of 95 engines, indicating limited but concerning recognition of its malicious nature. Registered through Dynadot Inc on December 28, 2025, the domain resolves to IP address 216.244.65.50 and utilizes a Let's Encrypt SSL certificate to appear trustworthy. Despite its recent creation, the low but nonzero detection rate suggests this scam is actively distributing and evading immediate blocklists.
Users who visited investpvf.com should immediately disconnect any connected wallets, revoke any unauthorized approvals, and transfer remaining funds to a secure wallet. Scan devices for malware, change passwords if credentials were entered, and report the domain to security platforms like PhishDestroy or Google Safe Browsing. Avoid interacting with any prompts or requests on this site, as it is a confirmed crypto drainer with elevated risk of financial theft.
威胁响应 Pipeline
公共封禁名单状态
已保存的截图
域名情报
技术细节DNS、SSL SAN、时间戳
ICANN OVERSIGHT
认证和 RAA 背景
认证和 RAA 背景
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
所用技术 · 5 identified
jQuery is a JavaScript library which is a free, open-source software designed to simplify HTML DOM tree traversal and manipulation, as well as event handling, CSS animation, and Ajax.
jquery.com 置信度 100%CreateJS is a suite of modular libraries and tools which work together or independently to enable interactive content on open web technologies via HTML5.
code.createjs.com 置信度 100%HTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 置信度 100%VirusTotal 分析
证据与外部报告
PD-20260515-E0D7F2 Recipient: abuse@dynadot.com 您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。