web-resolved[.]netlify[.]app
“dapp-resolved”
证据摘要
The domain web-resolved.netlify.app was observed serving a page titled “dapp‑resolved” that returned HTTP 404. The site is hosted on Netlify and presents an HSTS header, indicating HTTPS enforcement. The TLS certificate is issued by DigiCert Inc under the DigiCert Global G2 TLS RSA SHA256 2020 CA1 chain, confirming a legitimate certificate authority but offering no indication of malicious intent beyond the hosting platform. Network resolution points to the IP address 63.176.8.218, which belongs to Amazon.com, Inc. (AS16509) and geolocates to Germany. The domain’s authoritative nameservers are dns1.p04.nsone.net and dns2.p04.nsone.net, typical of Netlify‑provided DNS.
VirusTotal scans recorded nine detections out of ninety‑five security vendors, reinforcing the suspicion of abuse. The domain appears on four external blocklists, specifically PhishDestroy, Polkadot, Enkrypt, and Codeesura, all of which categorize it as a crypto‑related scam. The intelligence tags it as a “Crypto Scam” and the overall risk level is elevated. Current status is offline, and the HTTP response is a 404, suggesting the malicious payload has been removed or the site is no longer active.
Evidence does not reveal the exact phishing content, landing pages, or credential‑harvesting mechanisms, so the precise attack vector remains unconfirmed. Defenders should continue to block the domain and its associated IP at perimeter and DNS filtering layers, update threat intelligence feeds with the observed blocklist identifiers, and monitor for any re‑registration attempts on Netlify or other hosting providers. Ongoing watches on the AS16509 range are advisable given its frequent use for cloud‑based malicious infrastructure. Analysts should also review any recent alerts that reference the page title “dapp‑resolved” as it may indicate related campaigns.
Data Coverage
威胁响应 Pipeline
阻止列表覆盖
监控中的外部数据源 10 个 · 已存快照 2026年8月10日
检测时间线
-
域名状态
可访问 → 无法访问
-
Cloudflare Radar
已存储 Cloudflare Radar 扫描 · 打开扫描
技术
识别出 2 项高置信度技术
VirusTotal 分析
您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。
检查任意域名
使用存储的阻止列表、WHOIS、DNS 和公共扫描证据进行威胁分析
立即扫描举报网络钓鱼
将可疑域名提交至我们的威胁数据库——保护社区
报告实时威胁动态
最近的网络钓鱼报告和观察到的可用性变化
监控