victim-nomad[.]xyz
“Nomad | Bridge”
victim-nomad.xyz — 内容不可用 (HTTP 502). 品牌冒充:MetaMask; 诈骗类型:Crypto Scam. 证据摘要: VirusTotal 2/95 (alphaMountain.ai, Forcepoint ThreatSeeker); 1 external blocklist match (ScamSniffer); PhishDestroy score 58/100.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
The domain victim-nomad.xyz is a cryptocurrency phishing site engaged in brand impersonation targeting MetaMask users. It presented itself as a legitimate Nomad Bridge interface to deceive victims into entering wallet credentials or approving malicious transactions, though no drainer kit was confirmed. As of the latest verification, victim-nomad.xyz has been taken offline.
Technical indicators show victim-nomad.xyz was flagged by 2 of 95 VirusTotal security vendors, including alphaMountain.ai and Forcepoint ThreatSeeker. The domain appears on 2 security blocklists (PhishDestroy and ScamSniffer) but was not flagged by Google Safe Browsing. It was created on February 21, 2026, and resolved to the IPv6 address 2a06:98c1:3121::3, hosted on Cloudflare's network (AS13335) in the US. The SSL certificate was issued by WE1, and the observed page title was 'Nomad | Bridge'.
Victims of victim-nomad.xyz should immediately revoke any token approvals granted to unknown contracts using a tool like Etherscan's token approval checker. Move remaining funds to a new, secure wallet and monitor transaction history for unauthorized activity. Change MetaMask passwords and enable two-factor authentication on all accounts. Report the phishing domain to MetaMask's official support channels, the hosting provider (Cloudflare), and platforms like PhishTank or the Anti-Phishing Working Group to aid in takedown efforts.
威胁响应 Pipeline
公共封禁名单状态
VirusTotal 分析
证据与外部报告
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。