synthetlx[.]at
“synthetlx.at”
synthetlx.at — 未验证. 诈骗类型:Generic Phishing. 证据摘要: VirusTotal 9/91 (alphaMountain.ai, BitDefender, ESET, Fortinet, G-Data); URLQuery 12 alerts; Spamhaus DBL_PHISH; CF Radar malicious; PhishDestroy score 93/100. 注册商: Hosting concepts.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
This domain is flagged as a high-risk phishing threat targeting users of decentralized finance (DeFi) services. Analysis indicates synthetlx.at impersonates a legitimate cryptocurrency platform, likely Synthetix, to deceive victims into disclosing wallet credentials or transferring digital assets under false pretenses. The domain exhibits characteristics consistent with credential harvesting and financial fraud, including the use of lookalike branding and deceptive transaction prompts commonly associated with DeFi scams. Infrastructure analysis reveals synthetlx.at resolves to the IP address 185.53.179.136, an indicator previously linked to malicious campaigns. The domain appears on four security blocklists and is referenced in two AlienVault OTX threat intelligence pulses, suggesting active tracking by the cybersecurity community. Detection metrics include 11/95 security vendors on VirusTotal flagging the domain as malicious, while Gridinsoft assigns a trust score of 0/100. The domain was registered through Hosting Concepts B.V. (Registrar.eu), a registrar frequently observed in phishing operations. Additional defensive measures include blocking by MetaMask, PhishDestroy, SEAL, and Maltrail, further corroborating its malicious classification. Mitigation requires immediate action from both end users and network administrators. Users who interacted with synthetlx.at should revoke any connected wallet permissions, transfer assets to a new secure wallet, and monitor for unauthorized transactions. Network-level protections should include DNS filtering to block resolution of the domain and its associated IP, as well as implementing indicators of compromise (IOCs) such as 185.53.179.136 in intrusion detection systems. Organizations should educate users on identifying DeFi phishing tactics, particularly the use of lookalike domains and unsolicited transaction requests. Given the domain's current offline status, vigilance is advised for potential reemergence under alternative infrastructure.
网络安全情报
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Cloudflare DNS | www.synthetlx.at |
malicious | Sinkholed |
| OpenDNS | www.synthetlx.at |
phishing | Phishing Block |
| Hagezi Threat Feed | www.synthetlx.at |
malicious | Sinkholed |
| DNS4EU | www.synthetlx.at |
malicious | Sinkholed |
| DigiCert UltraDNS | euob.northwavepoint.com |
malicious | Sinkholed |
| Hagezi Threat Feed | yfdnzfa.com |
malicious | Sinkholed |
| DNS4EU | yfdnzfa.com |
malicious | Sinkholed |
| Quad9 DNS | yfdnzfa.com |
malicious | Sinkholed |
| DigiCert UltraDNS | yfdnzfa.com |
malicious | Sinkholed |
| DigiCert UltraDNS | s.cdn-fileserver.com |
malicious | Sinkholed |
| DigiCert UltraDNS | obseu.northwavepoint.com |
malicious | Sinkholed |
| DigiCert UltraDNS | l.cdn-fileserver.com |
malicious | Sinkholed |
威胁响应 Pipeline
公共封禁名单状态
VirusTotal 分析
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。