purchase2-blockdag-networks[.]pages[.]dev
“Become a Part Of BlockDAG Network | Buy BDAG Coins & Miners”
purchase2-blockdag-networks.pages.dev — 未验证. 证据摘要: VirusTotal 14/91 (alphaMountain.ai, BitDefender, CyRadar, ESET, Emsisoft); URLQuery 2 alerts; 1 external blocklist match (ScamSniffer); PhishDestroy score 97/100. 注册商: Cloudflare.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
This domain is currently under investigation for banking phishing activity, specifically targeting users through fraudulent cryptocurrency investment schemes. The page mimics legitimate blockchain services to harvest credentials and financial information, posing a direct risk to users engaging with purported BDAG coin purchases or mining operations. Analysis indicates the domain was registered on July 25, 2024, through Cloudflare, Inc., and resolves to the IP address 172.66.44.240, located in Canada. Despite its recent creation, the domain appears on two security blocklists and has been flagged by at least two independent threat intelligence sources. VirusTotal currently reports 0/95 detections, suggesting the infrastructure remains undetected by most security vendors. The SSL certificate is issued by Google Trust Services (WE1), which may lend a false sense of legitimacy to unsuspecting users. Mitigation requires immediate blocking of the domain and associated IP address within enterprise and consumer security controls. Network administrators should monitor for connections to 172.66.44.240 and inspect SSL certificates matching Google Trust Services WE1 for similar fraudulent patterns. Users should be educated to verify domain authenticity before entering financial or login credentials, particularly for cryptocurrency-related transactions. Suspicious activity should be reported to relevant financial institutions and cybersecurity response teams for further analysis.
网络安全情报
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Private YARA rules | purchase2-blockdag-networks.pages.dev/newfiles.js |
audit | Hunting_JS_WebAssembly |
| DNS4EU | purchase2-blockdag-networks.pages.dev |
malicious | Sinkholed |
威胁响应 Pipeline
公共封禁名单状态
所用技术 · 6 identified
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
Tag management system for deploying marketing and analytics tags.
tagmanager.google.comWeb analytics service tracking website traffic and user behavior.
marketingplatform.google.comConversion-tracking pixel by Meta — logs page views and custom events to Facebook/Instagram ad accounts.
www.facebook.comWeb infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
VirusTotal 分析
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。