crash-nft[.]xyz
“$CRASH Claims”
crash-nft.xyz — خطأ في الخادم (HTTP 502). نوع الاحتيال: Nft Scam. ملخص الأدلة: VirusTotal 3/91 (Fortinet, Gridinsoft, LevelBlue); PhishDestroy score 65/100. مسجّل النطاق: NiceNIC.
يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.
PhishDestroy identifies crash-nft.xyz as a recently activated crypto drainer domain designed to siphon digital assets from unsuspecting NFT collectors and cryptocurrency users. This fraudulent site masquerades as a legitimate NFT platform, leveraging social engineering tactics to trick visitors into connecting their wallets and authorizing malicious transactions. Security researchers have flagged the drainer kit used on this domain as a variant of the open-source “CryptDrainer” script, modified to evade basic detection and target high-value blockchain wallets. While no specific brand is being impersonated at this stage, the domain’s naming suggests an attempt to capitalize on the popularity of NFT projects and crash-related market narratives to lure victims. Domain analysis reveals several suspicious technical indicators. crash-nft.xyz currently shows 0 detections out of 95 on VirusTotal, indicating it has flown under the radar of most security vendors. The domain was registered through NICENIC INTERNATIONAL GROUP CO., LIMITED, a registrar known for accommodating high-risk or short-lived domains. It resolves to IP address 172.67.213.106 and was created on April 28, 2026, suggesting a very recent threat with minimal historical footprint. The domain is secured with a Let’s Encrypt SSL certificate, which provides a false sense of legitimacy. As of now, the domain has not been included in the Google Safe Browsing (GSB) blocklist, but its low detection rate and recent creation date indicate a rapidly evolving threat that requires immediate attention. This domain remains active and is actively monitored by threat intelligence teams. Users are strongly advised to avoid visiting crash-nft.xyz and to block the domain and its associated IP at the network level. Security researchers recommend blocking both the domain and IP (172.67.213.106) in firewall rules and DNS sinkholes. While the immediate risk is classified as under investigation, the presence of a crypto drainer kit and zero detections on VirusTotal signal a high potential for financial loss if left unchecked. Continued monitoring and community reporting are essential to prevent further victimization. Users should verify all NFT-related sites through official channels and use hardware wallets or transaction simulation tools before approving any blockchain interactions.
استخبارات أمن الشبكات Registrar context
مسار الاستجابة للتهديدات Pipeline
حالة قوائم الحظر العامة
لقطة محفوظة
معلومات النطاق
التفاصيل الفنيةDNS، أسماء المجال البديلة (SAN) في بروتوكول SSL، الطوابع الزمنية
ICANN OVERSIGHT
الاعتماد وسياق RAA
الاعتماد وسياق RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Latest Classified Outcome 2026-08-18 02:56:20 UTC
التقنيات · 4 identified
Hostinger is an employee-owned Web hosting provider and internet domain registrar.
www.hostinger.com ثقة 100٪Cloudflare Browser Insights is a tool that measures the performance of websites from the perspective of users.
www.cloudflare.com ثقة 100٪Cloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com ثقة 100٪HTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org ثقة 100٪تحليل VirusTotal
الأدلة والتقارير الخارجية
PD-20260501-23F811 Recipient: abuse@nicenic.net, abuse@gen.xyz هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب