aicapital[.]cyou
“The domain aicapital.cyou is powered by NicNames.com”
aicapital.cyou — لم يتم التحقق منها. نوع الاحتيال: Crypto Drainer. ملخص الأدلة: VirusTotal 3/91 (alphaMountain.ai, Gridinsoft, SOCRadar); 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 66/100. مسجّل النطاق: Nicnames.
يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.
PhishDestroy identifies aicapital.cyou as a live crypto drainer domain under active threat investigation due to its recent deployment and suspicious infrastructure alignment. This domain is currently operational and engaging in malicious activities designed to deceive users into connecting crypto wallets, which may result in asset drainage or credential compromise. aicapital.cyou was registered through NicNames, Inc, a registrar often leveraged in bulk malicious domain creation campaigns, and is actively resolving to IP address 159.203.143.218 while utilizing a Let's Encrypt SSL certificate for added legitimacy. Despite zero detections on VirusTotal as of the latest scan, the domain has already been blocked by MetaMask and SEAL, indicating high-risk classification by multiple security platforms.
This domain exhibits multiple red flags indicative of crypto drainer infrastructure. aicapital.cyou was created on May 02, 2026, a recent timestamp suggesting opportunistic deployment aligned with current market events or trends. It has been flagged by 2 of 95 VirusTotal vendors and currently resides on two security blocklists, including industry-leading threat intelligence feeds. The domain's hosting IP at 159.203.143.218 shows no established trust score and has not been previously indexed in reputable service whitelists. While the page title indicates use of NicNames' hosting infrastructure, this alone does not mitigate risk, as NicNames has been repeatedly observed in abuse reports tied to fraudulent domain registrations. The absence of detections does not equate to safety; rather, it reflects the evasive nature of this threat and its likely targeting of cryptocurrency users under time-sensitive conditions.
As of this advisory, aicapital.cyou remains active and unmitigated by major browsers or DNS filters, posing a direct threat to individuals visiting the site. Crypto drainers like this exploit user urgency—such as fake token launches or urgent wallet connection prompts—to trick victims into signing malicious transactions. Users who interact with this domain risk wallet compromise, fund loss, and credential exposure. Immediate action is required: block this domain at the DNS or endpoint level, flag all associated IPs and SSL certificates, and update corporate blocklists. End users should be warned against visiting aicapital.cyou and encouraged to verify URLs via official channels. Further, enterprises should scan network logs for outbound connections to 159.203.143.218 and inspect any internal hosts that resolved this domain. This threat is ongoing, and proactive monitoring is essential to prevent compromise.
استخبارات أمن الشبكات
مسار الاستجابة للتهديدات Pipeline
حالة قوائم الحظر العامة
لقطة محفوظة
معلومات النطاق
التفاصيل الفنيةDNS، أسماء المجال البديلة (SAN) في بروتوكول SSL، الطوابع الزمنية
نطاق SHORTDOT · أدلة عامة
.cyou
ShortDot zone evidence
ShortDot zone evidence
The linked repository preserves daily zone observations across seven ShortDot-operated TLDs, including registration volume and abuse-related indicators. This registry context is supporting background and is not an independent detection for the domain in this report.
ICANN OVERSIGHT
الاعتماد وسياق RAA
الاعتماد وسياق RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
تحليل VirusTotal
تحليل أداء الموقع
Google PageSpeed Insights — mobile performance audit of aicapital.cyou · checked May 4, 2026
الأدلة والتقارير الخارجية
هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب