lickedyou[.]xyz
“Connect Wallet”
lickedyou.xyz — المحتوى غير متوفر. انتحال العلامة التجارية: Genericcrypto; نوع الاحتيال: Crypto Scam. ملخص الأدلة: VirusTotal 2/93 (alphaMountain.ai, Forcepoint ThreatSeeker); URLScan malicious verdict; PhishDestroy score 56/100.
يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.
Analysis as of 24 July 2026 indicates that the domain lickedyou.xyz was registered on 21 February 2026. The site hosts a page titled “Connect Wallet”, consistent with a crypto‑draining phishing campaign. Hosting is provided through Cloudflare, as the domain resolves to IP address 188.114.96.3, which belongs to ASN 13335 (Cloudflare, Inc.) located in the United States. The authoritative nameservers are blair.ns.cloudflare.com and theo.ns.cloudflare.com, and the TLS certificate presented is identified as “WE1”.
The domain has been flagged by PhishDestroy and appears on a single public blocklist. On VirusTotal, two of ninety‑three scanning engines returned a positive classification, reinforcing the suspicion of malicious activity. Independent reputation scoring from Gridinsoft rates the site at 0 out of 100, indicating an extremely low trust level. The current operational status is offline, suggesting that the phishing infrastructure has been taken down or is no longer serving content.
Evidence gaps remain regarding the specific phishing kit used, any observed payload delivery, and the extent of victim impact, as no additional forensic artifacts have been publicly disclosed. Defenders should continue to monitor the associated IP address and Cloudflare ASN for any re‑use, enforce URL filtering for the exact domain, and include it in threat‑intel feeds. Organizations that employ crypto‑wallet integrations should educate users about unsolicited “Connect Wallet” prompts and verify URLs before entering credentials. Because the domain is already listed on at least one blocklist and has a zero trust score, immediate blocking is recommended while awaiting further indicators of compromise.
مسار الاستجابة للتهديدات Pipeline
حالة قوائم الحظر العامة
الاستخبارات الجنائية الرقمية
تحليل VirusTotal
الأدلة والتقارير الخارجية
هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب