raydium[.]co[.]com
raydium.co.com 网络钓鱼与安全检查
“Nur einen Moment…”
raydium.co.com — 服务器错误 (HTTP 502). 品牌冒充:Raydium; 诈骗类型:Crypto Scam. 证据摘要: VirusTotal 10/91 (ADMINUSLabs, ChainPatrol, alphaMountain.ai, AlphaSOC, BitDefender); 1 external blocklist match (ScamSniffer); PhishDestroy score 80/100.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
raydium.co.com is currently listed as an offline domain that was used to impersonate the Raydium brand in a crypto‑scam campaign. The site returned the page title “Nur einen Moment…”, which does not contain any brand references, and it lacked an SSL certificate, indicating the connection was unencrypted. DNS resolution pointed to 188.114.97.3, an address owned by Cloudflare, Inc. (AS13335) and located in the United States. The authoritative name servers are raquel.ns.cloudflare.com and rohin.ns.cloudflare.com, both Cloudflare‑managed, which is typical for fast‑flux or abuse‑resilient infrastructure.
Reputation scoring from Gridinsoft assigned a trust score of 0 out of 100, reflecting an extremely low confidence level. VirusTotal recorded nine detections out of ninety‑five scanned vendors, confirming that multiple security products flagged the domain as malicious. The domain appears on two independent blocklists—PhishDestroy and ScamSniffer—and is explicitly categorized as a crypto scam that masquerades as Raydium. Because the site is presently taken offline, active exploitation is unlikely, but the underlying IP address remains in use by Cloudflare and could be recycled for other malicious campaigns.
Defenders should continue to block the domain at perimeter and DNS layers, monitor for any re‑registration of the exact name or variations, and add the associated IP address to any network‑wide deny lists pending further verification. Continuous observation of Cloudflare‑hosted IP ranges for new Raydium‑related indicators is recommended, as well as periodic re‑scanning with multi‑engine services to capture any changes in detection status. Organizations that interact with Raydium services should educate users that the legitimate Raydium platform does not host domains under the “.co.com” suffix and that any request for cryptocurrency transactions from such URLs should be treated as suspicious.
威胁响应 Pipeline
公共封禁名单状态
取证情报
VirusTotal 分析
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。