opensealogusa[.]gitbook[.]io
“OpenSea Login | USA”
证据摘要
Analysis of opensealogusa.gitbook.io shows a active infrastructure that is deliberately mimicking the OpenSea brand. The domain resolves to IP address 172.64.147.209, an address owned by AS13335 Cloudflare, Inc. in the United States, and uses Cloudflare‑provided authoritative nameservers dahlia.ns.cloudflare.com and hugh.ns.cloudflare.com. Registration through Cloudflare, Inc. is recorded, and the site serves content over HTTP/3 with a Google Trust Services / WE1 SSL certificate, indicating a valid TLS configuration but offering no assurance of legitimacy. The page title returned by the server is "OpenSea Login | USA," directly targeting OpenSea users and confirming a brand‑impersonation intent.
The scam type is identified as wallet/seed phishing, a common vector for credential harvesting in the crypto space. Infrastructure checks reveal a HTTP 307 response, suggesting the site redirects visitors, a technique often used to funnel traffic to malicious payloads or credential‑capture pages. The domain appears on a single security blocklist and is explicitly blocked by PhishDestroy, demonstrating that at least one protective service has flagged the site. VirusTotal analysis reports twelve of ninety‑five scanners flagging the domain, and Gridinsoft assigns a trust score of zero out of one hundred, both reinforcing a high‑risk assessment.
The domain was created on March 30, 2014, indicating a long‑standing registration that may have been repurposed for malicious use. While the available data confirms the presence of brand impersonation and phishing indicators, the exact payload, server‑side behavior, and any additional malicious infrastructure remain unverified. Defenders should block the domain at perimeter firewalls and proxy filters, add the IP address to deny lists, monitor DNS queries for the associated nameservers, and educate users to avoid entering OpenSea credentials on any site with this title.
Data Coverage
威胁响应 Pipeline
阻止列表覆盖
监控中的外部数据源 10 个 · 已存快照 2026年8月10日
检测时间线
-
域名状态
可访问 → 无法访问
-
Cloudflare Radar
已存储 Cloudflare Radar 扫描 · 打开扫描
技术
识别出 2 项高置信度技术
VirusTotal 分析
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。
检查任意域名
使用存储的阻止列表、WHOIS、DNS 和公共扫描证据进行威胁分析
立即扫描举报网络钓鱼
将可疑域名提交至我们的威胁数据库——保护社区
报告实时威胁动态
最近的网络钓鱼报告和观察到的可用性变化
监控