MALICIOUS — CRITICAL
appmini[.]xyz
6 of 91 security engines flagged the domain; 2 public blocklists listed it (MetaMask, SEAL); the latest stored check returned HTTP 302.
- VirusTotal
- 6/91
- Blocklists
- 2 · MetaMask, SEAL
- التوفر
- آخر نشاط معروف · HTTP 302
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Notification and current-status evidence
The sent-report ledger records the first outgoing report at .
The recorded recipient is abuse-contact@sav.com.
The latest stored availability evidence still shows the domain reachable; 23 days has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
Jump to section
appmini.xyz — آخر نشاط معروف (HTTP 302). انتحال العلامة التجارية: Aave; نوع الاحتيال: Impersonation. ملخص الأدلة: VirusTotal 6/91 (alphaMountain.ai, CRDF, Forcepoint ThreatSeeker, Fortinet, Gridinsoft); URLQuery 1 alert; 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 83/100. مسجّل النطاق: Sav.com.
يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.
Evidence Digest
appmini.xyz is classified critical with an evidence score of 83/100. 6 of 91 security engines flagged the domain; 2 public blocklists listed it (MetaMask, SEAL). Registered 16 Jul 2026 via Sav.com, LLC, hosted on 172.67.159.198 (Cloudflare, Inc., CA). The latest stored check on 9 Aug 2026 returned HTTP 302 and includes a capture. 1 outgoing abuse report is recorded, most recently on 17 Jul 2026.
Stored generated summary (templated)cerebras · 16/07/2026
Retained for the record. This text repeats stored detection facts and is not presented as authored analysis.
Analysis of the domain appmini.xyz, created on July 16, 2026 and currently active, indicates a high‑risk generic phishing indicator. The domain is registered through Sav.com, LLC and is served by Cloudflare nameservers kayleigh.ns.cloudflare.com and zahir.ns.cloudflare.com. DNS resolution points to the IP address 172.67.159.198, which belongs to Cloudflare's edge network. VirusTotal has recorded a single positive detection out of 91 scanned security vendors, confirming at least one vendor has flagged the domain as malicious. The limited detection count suggests the domain is newly observed, and no additional intelligence such as malware kits or targeted brands has been disclosed. Because the domain resolves to a shared Cloudflare address, attribution of underlying hosting infrastructure is obscured, and further passive DNS or traffic analysis would be required to identify any supporting command‑and‑control servers. Defenders should block network connections to appmini.xyz and its resolved IP, monitor DNS queries for the domain, and consider adding the domain to web‑filter blocklists. Ongoing observation is advised to detect any escalation in detection counts or emergence of additional indicators.
نطاق تغطية البيانات12 recorded checks
استخبارات أمن الشبكات
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Hagezi Threat Feed | appmini.xyz |
malicious | Sinkholed |
مسار الاستجابة للتهديدات Pipeline
حالة قوائم الحظر العامة
لقطة محفوظة
معلومات النطاق
التفاصيل الفنيةDNS، أسماء المجال البديلة (SAN) في بروتوكول SSL، الطوابع الزمنية
ICANN OVERSIGHT
الاعتماد وسياق RAA
الاعتماد وسياق RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
تحليل VirusTotal
تحليل إعدادات الموقع
الأدلة والتقارير الخارجيةIndependent lookups and source reports
PD-20260717-6B1636 Recipient: abuse-contact@sav.com Victim safety and official reportingImmediate actions and verified reporting channels
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.