klaus[.]entry-cryptolist[.]app
“CRYPTOLIST”
证据摘要
Analysis of the domain klaus.entry-cryptolist.app indicates elevated risk consistent with cryptocurrency-themed phishing infrastructure. As of July 29, 2026, the domain resolves to IP address 188.114.96.3 but lacks configured nameservers, a common indicator of hastily deployed or bulletproof-hosted phishing pages. Twelve of ninety-one security vendors on VirusTotal have flagged this domain, suggesting detection by multiple independent engines but not yet universal consensus. The domain appears on at least one security blocklist and is actively blocked by PhishDestroy, a specialized anti-phishing service.
No registrar or hosting provider details are currently available, limiting attribution. The IP address belongs to a cloud provider frequently used for ephemeral phishing campaigns, though this alone does not confirm malicious intent. The domain name includes 'crypto,' which aligns with observed patterns in cryptocurrency credential theft and wallet-draining schemes, though the exact content of the site remains unconfirmed.
Defenders should treat this domain as active phishing infrastructure and prioritize blocking at DNS, proxy, or endpoint layers. If internal logs show connections to this domain, immediate investigation for compromised credentials or wallet access is recommended. Further analysis of the page content and associated wallet addresses would clarify the specific threat model, but current evidence supports proactive containment.
Data Coverage
网络安全情报
威胁响应 Pipeline
阻止列表覆盖
监控中的外部数据源 10 个 · 已存快照 2026年8月13日
检测时间线
-
域名状态
可访问 → 无法访问
域名情报
技术详情DNS、TLS 名称和时间戳
VirusTotal 分析
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。
检查任意域名
使用存储的阻止列表、WHOIS、DNS 和公共扫描证据进行威胁分析
立即扫描举报网络钓鱼
将可疑域名提交至我们的威胁数据库——保护社区
报告实时威胁动态
最近的网络钓鱼报告和观察到的可用性变化
监控