raydem[.]cc
raydem.cc 网络钓鱼与安全检查
“Website Created”
raydem.cc — 内容不可用 (HTTP 502). 品牌冒充:Celer; 诈骗类型:Brand Impersonation. 证据摘要: VirusTotal 5/91 (alphaMountain.ai, CRDF, Forcepoint ThreatSeeker, Gridinsoft, SOCRadar); PhishDestroy score 65/100. 注册商: NiceNIC.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
Analysis of the domain raydem.cc indicates it was actively involved in brand impersonation targeting Celer, a known blockchain interoperability platform. The domain was registered on August 23, 2025, through NiceNIC International Group Co., Limited, and resolved to the IP address 172.67.213.219, hosted on Cloudflare's infrastructure (AS13335) in the United States. No SSL certificate was detected, which is atypical for legitimate services and may indicate an attempt to evade encrypted traffic inspection or reduce operational costs. The domain's page title was recorded as 'Website Created,' a generic placeholder that provides limited insight into the specific content hosted. However, the scam type was explicitly classified as brand impersonation, aligning with the identified target, Celer.
At the time of reporting, the domain was flagged by three of 95 security vendors on VirusTotal, though this detection rate alone does not confirm the full scope of malicious activity. It also appeared on one security blocklist, further supporting its classification as suspicious infrastructure. Infrastructure analysis reveals the use of Cloudflare nameservers (athena.ns.cloudflare.com and quinton.ns.cloudflare.com), a common tactic to obscure hosting origins and enhance resilience against takedowns. The domain was blocked by PhishDestroy and assigned a Gridinsoft trust score of 0/100, reinforcing its high-risk status. As of July 24, 2026, raydem.cc is offline, though defenders should monitor for potential reactivation or migration to new domains.
Organizations are advised to review logs for connections to 172.67.213.219 or raydem.cc, particularly from users interacting with Celer-related services. Proactive blocking of the domain and IP at the network level is recommended to mitigate residual risk. Given the use of Cloudflare, defenders should also assess whether additional domains resolving to the same IP or nameservers exhibit similar patterns.
网络安全情报 Registrar context
威胁响应 Pipeline
公共封禁名单状态
Latest Classified Outcome 2026-08-08 02:38:56 UTC
VirusTotal 分析
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。