sleepingonc4[.]com
sleepingonc4.com 网络钓鱼与安全检查
“XRPL Wallet Connect”
sleepingonc4.com — 内容不可用 (HTTP 502). 品牌冒充:Ledger; 诈骗类型:Wallet/seed Phishing. 证据摘要: VirusTotal 1/93 (Fortinet); Spamhaus DBL_PHISH; PhishDestroy score 55/100. 注册商: NiceNIC.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
This domain, sleepingonc4.com, was registered on 23 February 2026 through NiceNIC International Group Co., Limited and is currently hosted behind Cloudflare infrastructure (ASN 13335, United States). DNS resolution points to IP address 104.21.20.188, which resolves to Cloudflare edge nodes; the domain uses Cloudflare nameservers david.ns.cloudflare.com and elisabeth.ns.cloudflare.com. No TLS certificate is presented for the site, indicating that HTTPS is not configured. The page title observed when the site was live reads “XRPL Wallet Connect”, aligning with a wallet/seed phishing campaign that claims to target Ledger users.
A single security blocklist, PhishDestroy, has flagged the domain, and it appears on one additional blocklist. Gridinsoft assigns a trust score of 0 out of 100, reflecting a high likelihood of malicious intent. VirusTotal analysis shows that one of ninety‑three scanning engines flagged the domain, corroborating the suspicion of abuse. The risk rating is elevated and the domain has been taken offline as of the report date.
Defenders should add the domain and its resolving IP address to deny‑list rules, monitor for any future re‑registration, and enforce strict outbound filtering for connections to Cloudflare‑served IPs that are not part of legitimate services. Because the site lacked SSL, any attempted HTTP interactions could be intercepted, further exposing credentials. Continuous observation of the associated IP range for similar phishing payloads is advised. At present, the primary evidence consists of registration data, DNS configuration, the observed page title, blocklist entries, low trust scoring, and the single VirusTotal detection; no additional payload or content analysis is available.
网络安全情报 Registrar context
威胁响应 Pipeline
公共封禁名单状态
已保存的截图
域名情报
技术细节DNS、SSL SAN、时间戳
ICANN OVERSIGHT
认证和 RAA 背景
认证和 RAA 背景
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Latest Classified Outcome 2026-08-08 04:19:19 UTC
VirusTotal 分析
存档证据
证据与外部报告
PD-20260223-9B5A82 Recipient: abuse@nicenic.net, abuse@verisign-grs.com, compliance@icann.org 您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。