paynote[.]my
paynote.my 网络钓鱼与安全检查
“Shapebtc official website. Best cryptocurrency exchange rates on 2025”
paynote.my — 内容不可用 (HTTP 502). 证据摘要: VirusTotal 16/95 (ADMINUSLabs, alphaMountain.ai, BitDefender, CRDF, CyRadar); 3 external blocklist matches (Polkadot, Enkrypt, Codeesura); PhishDestroy score 95/100. 注册商: Porkbun.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
PhishDestroy first observed paynote.my on Nov 18, 2025. The captured page title is “Shapebtc official website. Best cryptocurrency exchange rates on 2025”. Current evidence score: 95/100 (critical).
Positive findings are stored from 4 sources: VirusTotal, Polkadot, Enkrypt, and Codeesura. VirusTotal recorded 16 detections among 95 engines: ADMINUSLabs, alphaMountain.ai, BitDefender, CRDF, CyRadar, ESET, Forcepoint ThreatSeeker, Fortinet, G-Data, Gridinsoft, Lionic, Phishing Database, Seclookup, SOCRadar, Sophos, Webroot on Feb 23, 2026 at 06:48 UTC. Polkadot, Enkrypt, and Codeesura listed the hostname in the separate external-blocklist snapshot on Aug 8, 2026 at 02:20 UTC. Non-positive and contextual checks: AlienVault OTX listed 3 community pulse references (not vendor detections) on Mar 1, 2026 at 17:11 UTC. URLQuery recorded no positive detection; no observation timestamp was retained. Google Safe Browsing returned no flag on Mar 3, 2026 at 04:14 UTC. URLScan completed without a malicious verdict (score 0) on Jul 29, 2026 at 03:33 UTC. PhishStats returned no feed match on Mar 2, 2026 at 16:00 UTC.
HTTP 502 was recorded on Aug 7, 2026 at 01:22 UTC; content was unavailable. Registration records for the domain list Porkbun LLC as the registrar and Jul 29, 2025 as the creation date. At collection time, the hostname resolved to 62.60.226.213 on AS214351 (FEMOIT FEMO IT SOLUTIONS LIMITED, GB). The recorded endpoint location is Frankfurt am Main, DE. The stored server header is Apache/2.4.52 (Ubuntu). DOM analysis on Apr 23, 2026 at 11:23 UTC returned 0/100; the source detections above were recorded separately. The evidence archive retains 2 visual captures from PhishDestroy and URLScan.
The content indicators and 4 positive source findings support the current phishing classification. The stored fields do not identify an impersonated brand or victim interaction.
威胁响应 Pipeline
公共封禁名单状态
VirusTotal 分析
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。