md[.]payima[.]cc
This domain, md.payima.cc, is flagged as a generic phishing site specializing in crypto wallet credential theft. Analysis indicates the infrastructure mimics legitimate wallet services to deceive users into entering private keys or recovery phrases, likely employing a drainer kit to automate fund transfers. No direct brand impersonation is evident, but the domain name suggests an attempt to appear associated with cryptocurrency platforms, increasing its deceptive potential. Infrastructure analysis reveals the domain was registered on June 12, 2026, through Gname.com Pte. Ltd., a registrar frequently linked to high-risk domains. It resolves to the IP address 188.114.96.3, which has been associated with other phishing campaigns. VirusTotal reports 6 out of 95 security vendors flagging the domain as malicious, and it appears on one security blocklist. The SSL certificate, issued by Google Trust Services, provides a false sense of legitimacy while failing to mitigate the underlying threat. As of the latest assessment, md.payima.cc has been taken offline, reducing immediate exposure. However, the domain remains a residual risk due to its recent registration and historical malicious activity. Users who interacted with the domain should revoke any connected wallet permissions, monitor for unauthorized transactions, and reset credentials for associated accounts. Continuous vigilance is advised, as threat actors may re-deploy similar infrastructure under new domains.
威胁响应 Pipeline
阻止列表覆盖
监控中的外部数据源 10 个 · 已存快照 2026年8月10日
检测时间线
-
VirusTotal
5 → 6
已保存的截图
域名情报
技术详情DNS、TLS 名称和时间戳
VirusTotal 分析
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。
检查任意域名
使用存储的阻止列表、WHOIS、DNS 和公共扫描证据进行威胁分析
立即扫描举报网络钓鱼
将可疑域名提交至我们的威胁数据库——保护社区
报告实时威胁动态
最近的网络钓鱼报告和观察到的可用性变化
监控